CVE-2017-0371: Mediawiki

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.

Affected products

  • Mediawiki Mediawiki: before 1.23.16 (fixed in 1.23.16); from 1.24.0, before 1.27.2 (fixed in 1.27.2); from 1.28.0, before 1.28.1 (fixed in 1.28.1)

Published 2022-02-18. Last modified 2026-06-17.