Manual:$wgUseAjax

{{ {{TNTN|SettingSummary false in earlier versions (pre-1.10) }}
 * name=UseAjax
 * version_min=1.6.0
 * rev_introduced=13335
 * section=Ajax
 * range= boolean
 * default=true
 * summary=Enable AJAX support.

Enables AJAX support. Required by some extensions and optional features.

Before 1.8.0, enabling Ajax support implicitly activated auto-suggestion for the search bar. Between 1.8 and 1.19 it had to be enabled explicitly: see $wgAjaxSearch (for 1.8 to 1.13) and $wgEnableMWSuggest (for 1.13 to 1.19). It returned to being implicitly activated when $wgEnableMWSuggest was removed in 1.20.

Security
"$wgUseAjax = true;" was a security issue in 1.6.x up to 1.9.0:

An XSS injection vulnerability was located in the AJAX support module, affecting MediaWiki 1.6.x and up when the optional setting $wgUseAjax is enabled.

There is no danger in the default configuration, with $wgUseAjax off.

If you are using an extension based on the optional Ajax module, either disable it or upgrade to a version containing the fix:


 * 1.9: fixed in 1.9.3
 * 1.8: fixed in 1.8.4
 * 1.7: fixed in 1.7.3
 * 1.6: fixed in 1.6.10