Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vw7-qgh3-r4pc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.

An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.

EPSS

Процентиль: 59%
0.00388
Низкий

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 5.4
nvd
почти 6 лет назад

An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.

EPSS

Процентиль: 59%
0.00388
Низкий

Дефекты

CWE-732