CVE-2014-2853 | MediaWiki up to 1.22.6/1.21.9 InfoAction.php sortKey cross site scripting (Bug 63251 / Nessus ID 73804)
A vulnerability, which was classified as problematic, was found in MediaWiki up to 1.22.6/1.21.9. This affects an unknown part of the file mediawiki/includes/actions/InfoAction.php. The manipulation of the argument sortKey leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2014-2853. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.