CVE-2020-25814
- EPSS 0.34%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is tha...
CVE-2020-25815
- EPSS 0.39%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
CVE-2020-25827
- EPSS 0.24%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:51
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site le...
CVE-2020-25828
- EPSS 0.39%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:51
An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version of mw.message().parse() doesn't escape HTML. This affects both message contents (which are generally safe) and the parameters (whic...
CVE-2020-25869
- EPSS 0.27%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:56
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.
CVE-2020-15005
- EPSS 0.74%
- Veröffentlicht 24.06.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:36
In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized use...
CVE-2020-10959
- EPSS 0.27%
- Veröffentlicht 02.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:56:27
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
CVE-2020-12051
- EPSS 0.51%
- Veröffentlicht 21.04.2020 22:15:14
- Zuletzt bearbeitet 21.11.2024 04:59:11
The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In other words, the information can be retrieved via the ...
CVE-2020-10960
- EPSS 0.21%
- Veröffentlicht 03.04.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:56:27
In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquer...
CVE-2020-10534
- EPSS 0.32%
- Veröffentlicht 12.03.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:31
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ...