CVE-2014-5241: Mediawiki

Medium severity, CVSS 6.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with a restricted character set.

Affected products

  • Mediawiki Mediawiki: up to and including 1.19.17; version 1.19 only; version 1.19.0 only; version 1.19.1 only; version 1.19.2 only; version 1.19.3 only; …

Published 2014-08-22. Last modified 2026-06-17.