MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism for transcluded pages, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
2014-08-22T17:55:02.907
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mediawiki | mediawiki | ≤ 1.19.17 | Yes |
Application | mediawiki | mediawiki | 1.19 | Yes |
Application | mediawiki | mediawiki | 1.19 | Yes |
Application | mediawiki | mediawiki | 1.19 | Yes |
Application | mediawiki | mediawiki | 1.19.0 | Yes |
Application | mediawiki | mediawiki | 1.19.1 | Yes |
Application | mediawiki | mediawiki | 1.19.2 | Yes |
Application | mediawiki | mediawiki | 1.19.3 | Yes |
Application | mediawiki | mediawiki | 1.19.4 | Yes |
Application | mediawiki | mediawiki | 1.19.5 | Yes |
Application | mediawiki | mediawiki | 1.19.6 | Yes |
Application | mediawiki | mediawiki | 1.19.7 | Yes |
Application | mediawiki | mediawiki | 1.19.8 | Yes |
Application | mediawiki | mediawiki | 1.19.9 | Yes |
Application | mediawiki | mediawiki | 1.19.10 | Yes |
Application | mediawiki | mediawiki | 1.19.11 | Yes |
Application | mediawiki | mediawiki | 1.19.12 | Yes |
Application | mediawiki | mediawiki | 1.19.13 | Yes |
Application | mediawiki | mediawiki | 1.19.14 | Yes |
Application | mediawiki | mediawiki | 1.19.15 | Yes |
Application | mediawiki | mediawiki | 1.19.16 | Yes |
Application | mediawiki | mediawiki | 1.20.1 | Yes |
Application | mediawiki | mediawiki | 1.20.2 | Yes |
Application | mediawiki | mediawiki | 1.20.3 | Yes |
Application | mediawiki | mediawiki | 1.20.4 | Yes |
Application | mediawiki | mediawiki | 1.20.5 | Yes |
Application | mediawiki | mediawiki | 1.20.6 | Yes |
Application | mediawiki | mediawiki | 1.20.7 | Yes |
Application | mediawiki | mediawiki | 1.20.8 | Yes |
Application | mediawiki | mediawiki | 1.21.1 | Yes |
Application | mediawiki | mediawiki | 1.21.2 | Yes |
Application | mediawiki | mediawiki | 1.21.3 | Yes |
Application | mediawiki | mediawiki | 1.21.4 | Yes |
Application | mediawiki | mediawiki | 1.21.5 | Yes |
Application | mediawiki | mediawiki | 1.21.6 | Yes |
Application | mediawiki | mediawiki | 1.21.7 | Yes |
Application | mediawiki | mediawiki | 1.21.8 | Yes |
Application | mediawiki | mediawiki | 1.21.9 | Yes |
Application | mediawiki | mediawiki | 1.21.10 | Yes |
Application | mediawiki | mediawiki | 1.22.0 | Yes |
Application | mediawiki | mediawiki | 1.22.1 | Yes |
Application | mediawiki | mediawiki | 1.22.2 | Yes |
Application | mediawiki | mediawiki | 1.22.3 | Yes |
Application | mediawiki | mediawiki | 1.22.4 | Yes |
Application | mediawiki | mediawiki | 1.22.5 | Yes |
Application | mediawiki | mediawiki | 1.22.6 | Yes |
Application | mediawiki | mediawiki | 1.22.7 | Yes |
Application | mediawiki | mediawiki | 1.22.8 | Yes |
Application | mediawiki | mediawiki | 1.23.0 | Yes |
Application | mediawiki | mediawiki | 1.23.1 | Yes |