Description
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-32240 | In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:39:21.052Z
Reserved: 2021-12-24T00:00:00.000Z
Link: CVE-2021-45474
No data.
Status : Modified
Published: 2021-12-24T02:15:07.493
Modified: 2024-11-21T06:32:17.227
Link: CVE-2021-45474
OpenCVE Enrichment
No data.
Weaknesses
EUVD