Описание
An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.0 (включая)
cpe:2.3:a:widgets_project:widgets:*:*:*:*:*:mediawiki:*:*
EPSS
Процентиль: 59%
0.00388
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-74
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.
EPSS
Процентиль: 59%
0.00388
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-74