Description
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
Remediation
References
Related Vulnerabilities
Ruby on Rails CVE-2021-22902 Vulnerability (CVE-2021-22902)
MySQL Out-of-bounds Write Vulnerability (CVE-2020-15358)
WordPress 2.8.5 Multiple Vulnerabilities (2.8 - 2.8.5)
WordPress Plugin Verve Meta Boxes TimThumb Arbitrary File Upload (1.2.8)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2018-14720)