Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rxq7-cw42-v5ch

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью

Описание

includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php.

includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php.

EPSS

Процентиль: 73%
0.01527
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php.

CVSS3: 6.1
nvd
больше 6 лет назад

includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php.

CVSS3: 6.1
debian
больше 6 лет назад

includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.1 ...

EPSS

Процентиль: 73%
0.01527
Низкий