Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6j65-7rx3-56x5

Опубликовано: 25 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

EPSS

Процентиль: 49%
0.00256
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 4 лет назад

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

CVSS3: 6.1
redhat
около 4 лет назад

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

CVSS3: 6.1
nvd
около 4 лет назад

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

EPSS

Процентиль: 49%
0.00256
Низкий

Дефекты

CWE-79