PT-2020-20624 · Mediawiki+1 · Widgets Extension+1

Alexia

·

Published

2020-02-24

·

Updated

2021-07-21

·

CVE-2020-9382

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Widgets extension versions 1.4.0 and earlier
Description An issue was discovered in the Widgets extension for MediaWiki, where improper title sanitization allowed for the execution of any wiki page as a widget via MediaWiki's {{#widget:}} parser function.
Recommendations For versions 1.4.0 and earlier, consider disabling the {{#widget:}} parser function until a patch is available to prevent the execution of arbitrary wiki pages as widgets. Restrict access to the Widgets extension to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2069
ALT-PU-2021-2092
CVE-2020-9382

Affected Products

Alt Linux
Widgets Extension