PT-2020-6811 · Mediawiki+1 · Mediawiki+1

Published

2020-09-25

·

Updated

2024-03-06

·

CVE-2020-25828

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.31.10 and earlier MediaWiki versions 1.32.x through 1.34.3
Description An issue was discovered in the non-jqueryMsg version of mw.message().parse(), which doesn't escape HTML. This affects both message contents and the parameters, which can be based on user input. When jqueryMsg is loaded, it correctly accepts only whitelisted tags in message contents and escapes all parameters. However, situations with an unloaded jqueryMsg can occur, for example, on a wiki with no extensions installed, allowing a remote attacker to conduct a cross-site scripting (XSS) attack.
Recommendations For MediaWiki versions 1.31.10 and earlier, update to version 1.31.10 or later. For MediaWiki versions 1.32.x through 1.34.3, update to version 1.34.4 or later. As a temporary workaround, consider disabling the mw.message().parse() function until a patch is available. Restrict access to the Special:SpecialPages page on a wiki with no extensions installed to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3022
ALT-PU-2020-3055
BDU:2022-07044
BIT-MEDIAWIKI-2020-25828
CVE-2020-25828
DLA-2379-1
DSA-4767-1
GHSA-H8QX-MJ6V-2934
MGASA-2020-0381

Affected Products

Alt Linux
Mediawiki