CVE-2015-10073 is a critical cross-site scripting (XSS) vulnerability found in tinymighty WikiSEO version 1.2.1 on MediaWiki, specifically within the modifyHTML function of the WikiSEO.body.php file. This flaw allows remote attackers to inject malicious scripts through the 'content' argument, leading to a high-impact compromise of confidentiality, integrity, and availability. With a CVSS score of 9.6 (CRITICAL) and a FAUCET Risk Score of 92/100, it poses a significant threat. Although not listed on CISA's KEV catalog, the exploit has been publicly disclosed, and community discussion is notably high, indicating awareness. Users are strongly advised to upgrade to WikiSEO version 1.2.2 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.1CPE matchmatch criteria | cpe:2.3:a:tinymighty:wikiseo:1.2.1:*:*:*:*:mediawiki:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.