{"id":"CVE-2017-8811","details":"The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks.","modified":"2026-03-15T22:18:47.148515Z","published":"2017-11-15T08:29:00.720Z","related":["MGASA-2017-0429"],"references":[{"type":"ADVISORY","url":"https://www.debian.org/security/2017/dsa-4036"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1039812"},{"type":"FIX","url":"https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wikimedia/mediawiki","events":[{"introduced":"0"},{"last_affected":"798ceea8b6c75d241f8469873ea900787383c7b4"},{"introduced":"0"},{"last_affected":"34bc8899bf68e011fde9113c6857853cf91df0b8"},{"introduced":"0"},{"last_affected":"819c0d21addeed5336244cb9b776fe83a7b2279e"},{"introduced":"0"},{"last_affected":"438c3d6c41799cb2da58946a6d743d36c6ac3e33"},{"introduced":"0"},{"last_affected":"a112e4fa487183da2d03166988e2dd1ec23f2bfe"},{"introduced":"0"},{"last_affected":"a69ecd8e05a4d09fd50493102dd6d575b3f70cf3"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"1.27.3"},{"introduced":"0"},{"last_affected":"1.28.0"},{"introduced":"0"},{"last_affected":"1.28.1"},{"introduced":"0"},{"last_affected":"1.28.2"},{"introduced":"0"},{"last_affected":"1.29.0"},{"introduced":"0"},{"last_affected":"1.29.1"}]}}],"versions":["1.1.0","1.27.0","1.27.0-rc.0","1.27.0-rc.1","1.27.1","1.27.2","1.27.3","1.28.0","1.28.0-rc.0","1.28.0-rc.1","1.29.0","1.29.0-rc.0","1.29.0-rc.1","1.3.0beta1","1.5.0alpha1","1.5.0alpha2","1.5.0beta1","1.5.0beta2","1.5.0beta3","1.5.0beta4","1.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8811.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"9.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}