CVE-2020-26121
- EPSS 0.16%
- Veröffentlicht 27.09.2020 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:19:17
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a...
CVE-2020-25812
- EPSS 0.37%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to in...
CVE-2020-25813
- EPSS 0.37%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
CVE-2020-25814
- EPSS 0.34%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is tha...
CVE-2020-25815
- EPSS 0.39%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
CVE-2020-25827
- EPSS 0.24%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:51
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site le...
CVE-2020-25828
- EPSS 0.39%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:51
An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version of mw.message().parse() doesn't escape HTML. This affects both message contents (which are generally safe) and the parameters (whic...
CVE-2020-25869
- EPSS 0.27%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:56
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.
CVE-2020-26116
- EPSS 0.91%
- Veröffentlicht 27.09.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:19:16
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first ar...
CVE-2020-25596
- EPSS 0.09%
- Veröffentlicht 23.09.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:11
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault,...