PT-2021-23484 · Mediawiki+1 · Mediawiki+1

Suffusion_Of_Yellow

·

Published

2021-10-06

·

Updated

2024-03-06

·

CVE-2021-42045

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions through 1.36.2
Description An issue was discovered in SecurePoll in the Growth extension, where simple polls allow users to create alerts by changing their User-Agent HTTP header and submitting a vote.
Recommendations For versions through 1.36.2, update to a version that contains a fix for this issue to prevent users from creating alerts by manipulating the User-Agent header.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3561
ALT-PU-2022-1199
BIT-MEDIAWIKI-2021-42045
CVE-2021-42045

Affected Products

Alt Linux
Mediawiki