Description
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2012-5381)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-9548)
WordPress Plugin Frontend File Manager Multiple Vulnerabilities (18.2)
WordPress Plugin Vitamin Multiple Arbitrary File Disclosure Vulnerabilities (1.0.0)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6212)