PT-2020-12450 · Wikimedia+1 · Mediawiki+1
Sbassett
·
Published
2020-06-02
·
Updated
2024-03-06
·
CVE-2020-10959
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki versions prior to 1.35
MediaWiki versions prior to 1.34.0-rc.0
Description
The issue allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page. This is achieved by exploiting the
resources/src/mediawiki.page.ready/ready.js file in MediaWiki.Recommendations
For MediaWiki versions prior to 1.35, update to version 1.35 or later to resolve the issue.
For MediaWiki versions prior to 1.34.0-rc.0, update to version 1.34.0-rc.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
resources/src/mediawiki.page.ready/ready.js file until a patch is available.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Mediawiki