CVE-2014-5243 is a clickjacking vulnerability affecting MediaWiki versions before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2. The flaw stems from a lack of IFRAME protection for transcluded pages, allowing remote attackers to trick users into unintended actions via a crafted website. With a CVSS score of 4.3 (Medium), this vulnerability has a network-based attack vector and medium attack complexity, potentially leading to partial integrity compromise (e.g., unauthorized actions). There is no impact on confidentiality or availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion or media coverage, suggesting low public awareness and impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.19.17CPE matchmatch criteria | cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* | ||
1.19CPE matchmatch criteria | cpe:2.3:a:mediawiki:mediawiki:1.19:*:*:*:*:*:*:* | ||
1.19CPE matchmatch criteria | cpe:2.3:a:mediawiki:mediawiki:1.19:beta_1:*:*:*:*:*:* | ||
1.19CPE matchmatch criteria | cpe:2.3:a:mediawiki:mediawiki:1.19:beta_2:*:*:*:*:*:* | ||
1.19.0CPE matchmatch criteria | cpe:2.3:a:mediawiki:mediawiki:1.19.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.