Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2f58-vf6g-6p8x

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

MediaWiki Cross-site Scripting (XSS) vulnerability

An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().

Пакеты

Наименование

mediawiki/core

composer
Затронутые версииВерсия исправления

>= 1.32.0, < 1.34.3

1.34.3

Наименование

mediawiki/core

composer
Затронутые версииВерсия исправления

>= 1.35.0-rc.0, < 1.35.0

1.35.0

EPSS

Процентиль: 59%
0.00387
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().

CVSS3: 6.1
redhat
больше 5 лет назад

An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().

CVSS3: 6.1
nvd
больше 5 лет назад

An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().

CVSS3: 6.1
debian
больше 5 лет назад

An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34 ...

EPSS

Процентиль: 59%
0.00387
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79