Candidate: CVE-2013-1951 PublicDate: 2019-10-31 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1951 http://www.openwall.com/lists/oss-security/2013/04/16 https://phabricator.wikimedia.org/T48084 Description: A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_mediawiki: upstream: https://gerrit.wikimedia.org/r/gitweb?p=mediawiki%2Fcore.git;a=commit;h=c6528bb73b99de3ae6a5f3d8493e9dc8a1eb9120 upstream_mediawiki: released (1.20.4, 1.19.5) hardy_mediawiki: ignored (reached end-of-life) lucid_mediawiki: ignored (reached end-of-life) oneiric_mediawiki: ignored (reached end-of-life) precise_mediawiki: ignored (reached end-of-life) precise/esm_mediawiki: DNE (precise was needed) quantal_mediawiki: ignored (reached end-of-life) raring_mediawiki: not-affected (1:1.19.5-1) saucy_mediawiki: not-affected (1:1.19.5-1) trusty_mediawiki: not-affected (1:1.19.5-1) trusty/esm_mediawiki: DNE utopic_mediawiki: not-affected (1:1.19.5-1) vivid_mediawiki: not-affected (1:1.19.5-1) vivid/stable-phone-overlay_mediawiki: DNE vivid/ubuntu-core_mediawiki: DNE wily_mediawiki: not-affected (1:1.19.5-1) xenial_mediawiki: DNE yakkety_mediawiki: not-affected (1:1.19.5-1) zesty_mediawiki: not-affected (1:1.19.5-1) artful_mediawiki: not-affected (1:1.19.5-1) bionic_mediawiki: not-affected (1:1.19.5-1) cosmic_mediawiki: not-affected (1:1.19.5-1) disco_mediawiki: not-affected (1:1.19.5-1) eoan_mediawiki: not-affected (1:1.19.5-1) focal_mediawiki: not-affected (1:1.19.5-1) groovy_mediawiki: not-affected (1:1.19.5-1) hirsute_mediawiki: not-affected (1:1.19.5-1) impish_mediawiki: not-affected (1:1.19.5-1) jammy_mediawiki: not-affected (1:1.19.5-1) devel_mediawiki: not-affected (1:1.19.5-1)