CVE

Id
70148  
CVE No.
CVE-2014-2853  
Status
Candidate  
Description
Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.  
Phase
Assigned (20140414)  
Votes
None (candidate not yet proposed)  
Comments