MEDIUM6.1
GHSA-2rm7-xxx8-35jh
MediaWiki Cross-site Scripting (XSS)
Quick fix
GHSA-2rm7-xxx8-35jh — mediawiki/core: upgrade to the fixed version with the command below.
composer require mediawiki/core:^1.27.6Details
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/mediawiki/core
Introduced in:
1.27.0Fixed in: 1.27.6Fix
composer require mediawiki/core:^1.27.6Packagist/mediawiki/core
Introduced in:
1.30.0Fixed in: 1.30.2Fix
composer require mediawiki/core:^1.30.2Packagist/mediawiki/core
Introduced in:
1.31.0Fixed in: 1.31.2Fix
composer require mediawiki/core:^1.31.2References
- https://nvd.nist.gov/vuln/detail/CVE-2019-12471[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2019-12471.yaml[WEB]
- https://github.com/wikimedia/mediawiki[PACKAGE]
- https://lists.wikimedia.org/pipermail/wikitech-l/2019-June/092152.html[WEB]
- https://phabricator.wikimedia.org/T207603[WEB]
- https://seclists.org/bugtraq/2019/Jun/12[WEB]
- https://www.debian.org/security/2019/dsa-4460[WEB]