Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
| Software | From | Fixed in |
|---|---|---|
| mediawiki / mediawiki | 1.27.0 | 1.27.0.x |
| mediawiki / mediawiki | 1.28.0 | 1.28.0.x |
| mediawiki / mediawiki | 1.28.1 | 1.28.1.x |
| mediawiki / mediawiki | 1.27.2 | 1.27.2.x |
| mediawiki / mediawiki | - | 1.23.15.x |
| mediawiki / mediawiki | 1.27.1 | 1.27.1.x |
| debian / debian_linux | 7.0 | 7.0.x |
| debian / debian_linux | 9.0 | 9.0.x |