Back to search
CVE-2020-35475
Published: Dec 18, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. (The right column with the changeable groups is not affected and is escaped correctly.)
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://phabricator.wikimedia.org/T268917
x_refsource_MISC
DSA-4816
vendor-advisory
x_refsource_DEBIAN
FEDORA-2020-0be2d40e13
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now