Beveiligingsadvies

CVE-2020-27620

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-10-22 03:05:10
Laatst bijgewerkt 2024-08-04 16:18:44
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.