VDB
Sign up
MEDIUM6.1

GHSA-rj9p-8jxj-2ch4

MediaWiki Cross-site Scripting (XSS) vulnerability

Quick fix

GHSA-rj9p-8jxj-2ch4 — mediawiki/core: upgrade to the fixed version with the command below.

composer require mediawiki/core:^1.34.3

Details

An issue was discovered in MediaWiki 1.34.x before 1.34.3. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mediawiki/core
Introduced in: 1.34.0Fixed in: 1.34.3
Fixcomposer require mediawiki/core:^1.34.3
Packagist/mediawiki/core
Introduced in: 1.35.0-rc.0Fixed in: 1.35.0
Fixcomposer require mediawiki/core:^1.35.0

References