Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g3qp-m89q-7v8m

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.

MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.

EPSS

Процентиль: 70%
0.00623
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.

nvd
больше 11 лет назад

MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.

debian
больше 11 лет назад

MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 ...

EPSS

Процентиль: 70%
0.00623
Низкий

Дефекты

CWE-20