CVE-2012-1582
Publication date 9 September 2012
Last updated 24 July 2024
Ubuntu priority
Description
Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mediawiki | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |