CVE-2017-0372

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
13/04/2018
Last modified:
17/05/2018

Description

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.23.15 (including)
cpe:2.3:a:mediawiki:mediawiki:1.27.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.27.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.27.2:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.28.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.28.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*