Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-51704

Опубликовано: 22 дек. 2023
Источник: debian
EPSS Низкий

Описание

An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mediawikifixed1:1.39.6-1package
mediawikifixed1:1.39.7-1~deb12u1bookwormpackage

Примечания

  • https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/TDBUBCCOQJUT4SCHJNPHKQNPBUUETY52/

  • https://phabricator.wikimedia.org/T347726

EPSS

Процентиль: 48%
0.00248
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.

CVSS3: 6.3
redhat
больше 1 года назад

An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.

CVSS3: 6.1
nvd
больше 1 года назад

An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.

CVSS3: 6.1
redos
около 1 года назад

Уязвимость mediawiki

CVSS3: 6.1
github
больше 1 года назад

An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.

EPSS

Процентиль: 48%
0.00248
Низкий