Vulnerability Bulletins |
DSA-3046 mediawiki - security update |
|
| Affected software | Debian |
|
It was reported that MediaWiki, a website engine for collaborative work,allowed to load user-created CSS on pages where user-created JavaScriptis not allowed. A wiki user could be tricked into performing actions bymanipulating the interface from CSS, or JavaScript code being executedfrom CSS, on security-wise sensitive pages like Special:Preferences andSpecial:UserLogin. This update removes the separation of CSS andJavaScript module allowance. More info: https://www.debian.org/security/2014/dsa-3046 |
|






