// For flags

CVE-2014-5241

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with a restricted character set.

El endpoint JSONP en includes/api/ApiFormatJson.php en MediaWiki anterior a 1.19.18, 1.20.x hasta 1.22.x anterior a 1.22.9, y 1.23.x anterior a 1.23.2 acepta ciertos valores largos de devolución de llamada y no restringe los bytes iniciales de una respuesta JSONP, lo que permite a atacantes remotos realizar ataques de CSRF, y obtener información sensible, a través de un elemento OBJECT manipulado con contenido SWF consistente con un juego de caracteres restringido.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-08-14 CVE Reserved
  • 2014-08-22 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2024-08-20 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
<= 1.19.17
Search vendor "Mediawiki" for product "Mediawiki" and version " <= 1.19.17"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19"
beta_1
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19"
beta_2
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.0
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.0"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.1
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.1"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.2
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.2"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.3
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.3"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.4
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.4"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.5
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.5"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.6
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.6"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.7
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.7"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.8
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.8"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.9
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.9"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.10
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.10"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.11
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.11"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.12
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.12"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.13
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.13"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.14
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.14"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.15
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.15"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.19.16
Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.16"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.20.1
Search vendor "Mediawiki" for product "Mediawiki" and version "1.20.1"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.20.2
Search vendor "Mediawiki" for product "Mediawiki" and version "1.20.2"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.20.3
Search vendor "Mediawiki" for product "Mediawiki" and version "1.20.3"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.20.4
Search vendor "Mediawiki" for product "Mediawiki" and version "1.20.4"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.20.5
Search vendor "Mediawiki" for product "Mediawiki" and version "1.20.5"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.20.6
Search vendor "Mediawiki" for product "Mediawiki" and version "1.20.6"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.20.7
Search vendor "Mediawiki" for product "Mediawiki" and version "1.20.7"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.20.8
Search vendor "Mediawiki" for product "Mediawiki" and version "1.20.8"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.1
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.1"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.2
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.2"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.3
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.3"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.4
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.4"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.5
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.5"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.6
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.6"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.7
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.7"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.8
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.8"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.9
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.9"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.21.10
Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.10"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.22.0
Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.0"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.22.1
Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.1"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.22.2
Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.2"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.22.3
Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.3"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.22.4
Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.4"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.22.5
Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.5"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.22.6
Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.6"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.22.7
Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.7"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.22.8
Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.8"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.23.0
Search vendor "Mediawiki" for product "Mediawiki" and version "1.23.0"
-
Affected
Mediawiki
Search vendor "Mediawiki"
Mediawiki
Search vendor "Mediawiki" for product "Mediawiki"
1.23.1
Search vendor "Mediawiki" for product "Mediawiki" and version "1.23.1"
-
Affected