CVE-2021-46150
- EPSS 0.18%
- Veröffentlicht 10.01.2022 14:11:29
- Zuletzt bearbeitet 21.11.2024 06:33:41
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog allows CheckUser XSS because of date mishandling, as demonstrated by an XSS payload in MediaWiki:October.
CVE-2021-46148
- EPSS 0.25%
- Veröffentlicht 10.01.2022 14:11:28
- Zuletzt bearbeitet 21.11.2024 06:33:41
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged users can view confidential information (e.g., IP addresses and User-Agent headers for election traffic) on a testwiki SecurePoll in...
CVE-2021-46149
- EPSS 0.27%
- Veröffentlicht 10.01.2022 14:11:28
- Zuletzt bearbeitet 21.11.2024 06:33:41
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service (resource consumption) can be accomplished by searching for a very long key in a Language Name Search.
CVE-2021-46146
- EPSS 0.16%
- Veröffentlicht 10.01.2022 14:11:27
- Zuletzt bearbeitet 21.11.2024 06:33:41
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.
CVE-2021-46147
- EPSS 0.11%
- Veröffentlicht 10.01.2022 14:11:27
- Zuletzt bearbeitet 21.11.2024 06:33:41
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.
CVE-2021-45471
- EPSS 0.31%
- Veröffentlicht 24.12.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:16
In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.
CVE-2021-45472
- EPSS 0.26%
- Veröffentlicht 24.12.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:16
In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.
CVE-2021-45473
- EPSS 0.33%
- Veröffentlicht 24.12.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:17
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).
CVE-2021-45474
- EPSS 0.26%
- Veröffentlicht 24.12.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:17
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
CVE-2021-44858
- EPSS 0.27%
- Veröffentlicht 20.12.2021 09:15:06
- Zuletzt bearbeitet 21.11.2024 06:31:37
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one...