Vulnerability Description
The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is disclosing the client's IP address). This can occur within a talk page topical header that is viewed within a mobile (MobileFrontend) context.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | 1.34 |
Related Weaknesses (CWE)
References
- https://gerrit.wikimedia.org/r/q/Ida471291f1698387a26736931ab17e6899e05b51PatchVendor Advisory
- https://phabricator.wikimedia.org/T240487Third Party Advisory
- https://gerrit.wikimedia.org/r/q/Ida471291f1698387a26736931ab17e6899e05b51PatchVendor Advisory
- https://phabricator.wikimedia.org/T240487Third Party Advisory
FAQ
What is CVE-2019-19910?
CVE-2019-19910 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is d...
How severe is CVE-2019-19910?
CVE-2019-19910 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19910?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Mediawiki.