PT-2020-6809 · Mediawiki+1 · Mediawiki+1

Published

2020-09-24

·

Updated

2024-03-06

·

CVE-2020-25812

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.34.x through 1.34.3
Description An issue was discovered in MediaWiki where the NS filter on Special:Contributions uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML. The vulnerability exists due to a lack of protection of the web page structure, which can allow a remote attacker to conduct a cross-site scripting (XSS) attack.
Recommendations For MediaWiki versions 1.34.x through 1.34.3, update to version 1.34.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Special:Contributions page until a patch is available. Additionally, avoid using unescaped messages as keys in the option key for an HTMLForm specifier to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3022
ALT-PU-2020-3055
BDU:2022-07042
BIT-MEDIAWIKI-2020-25812
CVE-2020-25812
DSA-4767-1
GHSA-RJ9P-8JXJ-2CH4
MGASA-2020-0381

Affected Products

Alt Linux
Mediawiki