VDB

GCVE-110-MAGEIA-2014-506

GCVE-110-MAGEIA-2014-506
Advisory Published
Vulnetix · Advisory published December 3, 2014
In MediaWiki before 1.23.7, a missing CSRF check could allow reflected XSS on wikis that allow raw HTML (CVE-2014-9276). MediaWiki's <cross-domain-policy> mangling, in MediaWiki before 1.23.7, could allow an article editor to inject code into API consumers that blindly unserialize PHP representations of the page from the API (CVE-2014-9277). This update provides MediaWiki 1.23.7, which fixes these security issues and other bugs.

Affected Products

VendorProductVersionsPlatforms
Mageiamediawiki0 (affected), 1.23.7-1.mga4 (unaffected)

Browse GCVE Records

74,355 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›