PT-2021-23487 · Mediawiki+1 · Mediawiki+1

Urbanecm_Wmf

·

Published

2021-10-06

·

Updated

2024-03-06

·

CVE-2021-42048

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions through 1.36.2
Description An issue was discovered in the Growth extension in MediaWiki. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits.
Recommendations For MediaWiki versions through 1.36.2, update to a version that contains a fix for this issue to prevent arbitrary JavaScript code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3561
ALT-PU-2022-1199
BIT-MEDIAWIKI-2021-42048
CVE-2021-42048

Affected Products

Alt Linux
Mediawiki