CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wikimedia 1Wikidata Query Gui Nov 21, 2024 Nov 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, aka XSS. This was addressed by introduci...Show more |
1Wikimedia 1Wikidata Query Gui Nov 21, 2024 Nov 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entities. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query S...Show more |
1Wikimedia 1Wikidata Query Gui Nov 21, 2024 Nov 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of results and number of milliseconds. NOTE: this GUI code is no longer bundled wit...Show more |