Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rpm7-qhmh-9jvh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.

The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.

EPSS

Процентиль: 54%
0.00315
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.

EPSS

Процентиль: 54%
0.00315
Низкий

Дефекты

CWE-79