PT-2020-17369 · Wikimedia+2 · Mediawiki+2
Daimona
·
Published
2020-12-21
·
Updated
2024-03-06
·
CVE-2020-35622
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki versions through 1.35.1
GlobalUsage extension for MediaWiki versions through 1.35.1
Description
An issue was discovered in the GlobalUsage extension for MediaWiki. The
SpecialGlobalUsage.php file calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function was not being properly escaped, allowing for XSS under certain conditions.Recommendations
For MediaWiki versions through 1.35.1, update to a version that properly escapes the
$page variable within the formatItem function to prevent XSS.
For the GlobalUsage extension, ensure that the WikiMap::makeForeignLink function is called safely and the $page variable is properly escaped to mitigate the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Globalusage Extension
Mediawiki