← Back

CVE-2020-35475

nvd nist
Published: Dec 18, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. (The right column with the changeable groups is not affected and is escaped correctly.)

Affected (3)

1 product
Mediawiki
1 product
Debian Linux
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.35.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 33

References (8)

Source: cve@mitre.org
Mailing ListRelease NotesVendor Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.