CRITICAL

CVE-2017-0372

CVSS v3

9.8

CRITICAL

EPSS Score

58.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

Technical details

Published
4/13/2018

Frequently asked questions

What is CVE-2017-0372?

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

Is CVE-2017-0372 actively exploited?

Active exploitation of CVE-2017-0372 has not been confirmed. The EPSS score is 58.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2017-0372?

CVE-2017-0372 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2017-0372 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

Other 2017 vulnerabilities worth triaging

Ranked by exploit probability (EPSS).