Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter, which is not properly handled in an error page, related to "ForeignAPI images."
| Software | From | Fixed in |
|---|---|---|
| mediawiki / mediawiki | - | 1.23.9.x |
| mediawiki / mediawiki | 1.24.2 | 1.24.2.x |
| mediawiki / mediawiki | 1.24.0 | 1.24.0.x |
| mediawiki / mediawiki | 1.24.1 | 1.24.1.x |
| mediawiki / mediawiki | 1.25.1 | 1.25.1.x |
| mediawiki / mediawiki | 1.25.0 | 1.25.0.x |