VYPR
Unrated severityNVD Advisory· Published Sep 9, 2012· Updated Jun 16, 2026

CVE-2012-1582

CVE-2012-1582

Description

Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • MediaWiki/Mediawiki12 versions
    cpe:2.3:a:mediawiki:mediawiki:1.17:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:mediawiki:mediawiki:1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17:beta_1:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18:beta_1:*:*:*:*:*:*
    • (no CPE)range: >=1.17.0, <1.17.3 || >=1.18.0, <1.18.2

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.