Description
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
Remediation
References
Related Vulnerabilities
OpenSSL Improper Certificate Validation Vulnerability (CVE-2021-3450)
WordPress Plugin Sign-up Sheets Cross-Site Scripting (1.0.13)
Oracle Database Server CVE-2010-2412 Vulnerability (CVE-2010-2412)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-7486)
WordPress Plugin Xtreme Locator Dealer Locator SQL Injection (1.5)