PT-2020-2139 · Mediawiki+1 · Mediawiki+1

Yair_Rand

·

Published

2020-03-29

·

Updated

2024-03-06

·

CVE-2020-10960

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.34.1
Description The issue in MediaWiki is related to the lack of proper output encoding or escaping, which can be exploited by a remote attacker to impact data integrity. Users can add various Cascading Style Sheets (CSS) classes to arbitrary DOM nodes via HTML content within a MediaWiki page, affecting what content is shown or hidden in the user interface. This occurs because jquery.makeCollapsible allows applying an event handler to any CSS selector. There is no known way to exploit this for cross-site scripting (XSS).
Recommendations For versions prior to 1.34.1, update to version 1.34.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of jquery.makeCollapsible to prevent applying event handlers to arbitrary CSS selectors.

Exploit

Fix

Special Elements Injection

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1642
ALT-PU-2020-2249
BDU:2020-02036
BIT-MEDIAWIKI-2020-10960
CVE-2020-10960
DSA-4651-1
GHSA-PFM2-MQWJ-GGM5
MGASA-2020-0167

Affected Products

Alt Linux
Mediawiki