VDB
Sign up
MEDIUM

GHSA-6h86-9r5g-f2h5

Cross-site scripting vulnerability in includes/actions/InfoAction.php

Quick fix

GHSA-6h86-9r5g-f2h5 — mediawiki/core: upgrade to the fixed version with the command below.

composer require mediawiki/core:^1.21.9

Details

Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mediawiki/core
Introduced in: 0Fixed in: 1.21.9
Fixcomposer require mediawiki/core:^1.21.9
Packagist/mediawiki/core
Introduced in: 1.22.0Fixed in: 1.22.6
Fixcomposer require mediawiki/core:^1.22.6

References