PT-2020-12450 · Wikimedia+1 · Mediawiki+1

Sbassett

·

Published

2020-06-02

·

Updated

2024-03-06

·

CVE-2020-10959

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35 MediaWiki versions prior to 1.34.0-rc.0
Description The issue allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page. This is achieved by exploiting the resources/src/mediawiki.page.ready/ready.js file in MediaWiki.
Recommendations For MediaWiki versions prior to 1.35, update to version 1.35 or later to resolve the issue. For MediaWiki versions prior to 1.34.0-rc.0, update to version 1.34.0-rc.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the resources/src/mediawiki.page.ready/ready.js file until a patch is available.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3022
ALT-PU-2020-3055
BIT-MEDIAWIKI-2020-10959
CVE-2020-10959
GHSA-MQHW-WQ8P-VF5R

Affected Products

Alt Linux
Mediawiki