VWE-2013-0038 Printable Version
This page is a chapter in Info Known Vulnerabilities
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name Unreasonable Vulnerability VWE-ID VWE-2013-0038 Related Report #3237 Severity HIGH Exploit Difficulty EASY Platform Affects all platforms supported by the vulnerable versions. Description HTML/Javascript injection. Edit reasons are displayed in history entries with HTML entities unescaped.
Discovered July 25, 2013 Resolved July 30, 2013 Patches Available 4.0.0 Beta 4
3.0.20 Patch Level 1Workaround Update permissions so that no users can view any special pages or the history tab.