PT-2021-3353 · Mediawiki+1 · Mediawiki+1

Grunny

·

Published

2021-04-06

·

Updated

2024-03-06

·

CVE-2021-30157

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.31.12 and earlier MediaWiki versions 1.32.x through 1.35.x before 1.35.2
Description The issue exists due to the lack of protection for the web page structure, allowing a remote attacker to conduct cross-site scripting (XSS) attacks. On ChangesList special pages, such as Special:RecentChanges and Special:Watchlist, some label messages are output in HTML unescaped, leading to XSS.
Recommendations For MediaWiki versions 1.31.12 and earlier, update to version 1.31.12 or later. For MediaWiki versions 1.32.x through 1.35.x before 1.35.2, update to version 1.35.2 or later. As a temporary workaround, consider restricting access to the ChangesList special pages, such as Special:RecentChanges and Special:Watchlist, until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1712
ALT-PU-2021-2091
BDU:2021-03171
BIT-MEDIAWIKI-2021-30157
CVE-2021-30157
DSA-4889-1

Affected Products

Alt Linux
Mediawiki