PT-2021-19422 · Mediawiki+1 · Pageforms+2

Alex Winkler

+1

·

Published

2021-04-22

·

Updated

2024-03-06

·

CVE-2021-31551

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions through 1.35.2 PageForms extension for MediaWiki versions through 1.35.2
Description An issue was discovered in the PageForms extension for MediaWiki, allowing for XSS on certain PageForms-managed MediaWiki pages. This is achieved through crafted payloads for Token-related query parameters.
Recommendations For MediaWiki versions through 1.35.2, update to a version that contains a fix for this issue. For PageForms extension for MediaWiki versions through 1.35.2, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1991
ALT-PU-2021-2091
BIT-MEDIAWIKI-2021-31551
CVE-2021-31551

Affected Products

Alt Linux
Mediawiki
Pageforms