Remote Code Injection via Headline ID Attribute in MediaWiki

Remote Code Injection via Headline ID Attribute in MediaWiki

CVE-2017-8812 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:N

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.

Learn more about our Web Application Penetration Testing UK.