Security Advisory

CVE-2021-36131

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-07-02 13:00:06
Last updated 2024-08-04 00:47:43
Assigner mitre
State PUBLISHED

Description

An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a privileged user could inject arbitrary HTML and JavaScript within various data fields. The attack could easily propagate across many pages for many users.