The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name Unreasonable Vulnerability VWE-ID VWE-2013-0038 Related Report #3237 Severity HIGH Exploit Difficulty EASY Platform Affects all platforms supported by the vulnerable versions. Description HTML/Javascript injection. Edit reasons are displayed in history entries with HTML entities unescaped.
Discovered July 25, 2013 Resolved July 30, 2013 Patches Available 4.0.0 Beta 4
3.0.20 Patch Level 1Workaround Update permissions so that no users can view any special pages or the history tab.
Sub-Categories of VWE-2013-0038
-
#
-
# (cont.)
-
# (cont.)