MediaWiki Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability - CVE-2017-8809 - Vulnerability Database
MediaWiki Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability - CVE-2017-8809
Critical
Reference:
CVE-2017-8809
Title:
MediaWiki Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
Overview:
api.php in MediaWiki before 1.27.4 1.28.x before 1.28.3 and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.