CVE-2021-46146
- EPSS 0.16%
- Veröffentlicht 10.01.2022 14:11:27
- Zuletzt bearbeitet 21.11.2024 06:33:41
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.
CVE-2021-46147
- EPSS 0.11%
- Veröffentlicht 10.01.2022 14:11:27
- Zuletzt bearbeitet 21.11.2024 06:33:41
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.
CVE-2021-45471
- EPSS 0.31%
- Veröffentlicht 24.12.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:16
In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.
CVE-2021-45472
- EPSS 0.26%
- Veröffentlicht 24.12.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:16
In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.
CVE-2021-45473
- EPSS 0.33%
- Veröffentlicht 24.12.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:17
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).
CVE-2021-45474
- EPSS 0.26%
- Veröffentlicht 24.12.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:17
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
CVE-2021-44858
- EPSS 0.42%
- Veröffentlicht 20.12.2021 09:15:06
- Zuletzt bearbeitet 21.11.2024 06:31:37
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one...
CVE-2021-44857
- EPSS 0.15%
- Veröffentlicht 17.12.2021 04:15:39
- Zuletzt bearbeitet 21.11.2024 06:31:37
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by action=mcrrestore to replace the content of any arbitrary page (that the user doesn't have edit right...
CVE-2021-45038
- EPSS 0.33%
- Veröffentlicht 17.12.2021 04:15:39
- Zuletzt bearbeitet 21.11.2024 06:31:50
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.
CVE-2021-41798
- EPSS 0.16%
- Veröffentlicht 11.10.2021 08:15:06
- Zuletzt bearbeitet 21.11.2024 06:26:46
MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.