Vulnerability Description
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | < 1.23.16 |
References
- https://phabricator.wikimedia.org/T140591Issue TrackingPatchVendor Advisory
- https://phabricator.wikimedia.org/T68404ExploitIssue TrackingPatch
- https://phabricator.wikimedia.org/T140591Issue TrackingPatchVendor Advisory
- https://phabricator.wikimedia.org/T68404ExploitIssue TrackingPatch
FAQ
What is CVE-2017-0371?
CVE-2017-0371 is a vulnerability with a CVSS score of 7.5 (HIGH). MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title ...
How severe is CVE-2017-0371?
CVE-2017-0371 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-0371?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Mediawiki.