MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-8808 - Vulnerability Database
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-8808
Medium
Reference:
CVE-2017-8808
Title:
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
MediaWiki before 1.27.4 1.28.x before 1.28.3 and 1.29.x before 1.29.2 has XSS when the wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.