PT-2020-16223 · Wikimedia+1 · Mediawiki+1

Published

2020-09-25

·

Updated

2024-03-06

·

CVE-2020-25815

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.32.x through 1.34.x before 1.34.4
Description An issue was discovered where the LogEventList::getFiltersDesc function is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
Recommendations For MediaWiki versions 1.32.x through 1.34.x before 1.34.4, update to version 1.34.4 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3022
ALT-PU-2020-3055
BIT-MEDIAWIKI-2020-25815
CVE-2020-25815
DSA-4767-1
GHSA-2F58-VF6G-6P8X
MGASA-2020-0381

Affected Products

Alt Linux
Mediawiki