PT-2021-3354 · Mediawiki+1 · Mediawiki+1

Grunny

·

Published

2021-04-06

·

Updated

2024-03-06

·

CVE-2021-30154

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.31.12 MediaWiki versions 1.32.x through 1.35.x before 1.35.2
Description An issue in MediaWiki leads to XSS due to the output of mediastatistics-header-* messages in HTML unescaped on Special:NewFiles. This could allow a remote attacker to impact the confidentiality and integrity of protected information.
Recommendations For MediaWiki versions prior to 1.31.12, update to version 1.31.12 or later. For MediaWiki versions 1.32.x through 1.35.x before 1.35.2, update to version 1.35.2 or later. As a temporary workaround, consider restricting access to the Special:NewFiles page until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1712
ALT-PU-2021-2091
BDU:2021-03174
BIT-MEDIAWIKI-2021-30154
CVE-2021-30154
DSA-4889-1

Affected Products

Alt Linux
Mediawiki