CVE-2012-4378

Source
https://cve.org/CVERecord?id=CVE-2012-4378
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2012-4378.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2012-4378
Downstream
Published
2017-10-26T20:29:00Z
Modified
2026-04-10T03:42:27.075355Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php.

References

Affected packages