Cross-site scripting (XSS) vulnerability in pages/TalkpageHistoryView.php in the LiquidThreads (LQT) extension 2.x and possibly 3.x for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to inject arbitrary web script or HTML via a thread subject.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2013-09-11T14:00:00

Updated: 2024-08-06T16:38:01.857Z

Reserved: 2013-06-12T00:00:00

Link: CVE-2013-4308

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-09-12T13:31:13.247

Modified: 2017-08-29T01:33:37.183

Link: CVE-2013-4308

cve-icon Redhat

No data.