An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript via the setchange log.
References
Link | Resource |
---|---|
https://gerrit.wikimedia.org/r/q/I7aeaa6e4de5ccaa5eeb6bf4fb00c96b01d5fea35 | Patch Vendor Advisory |
https://phabricator.wikimedia.org/T291696 | Exploit Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-10-06T20:28:43
Updated: 2021-10-06T20:28:43
Reserved: 2021-10-06T00:00:00
Link: CVE-2021-42041
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-10-06T21:15:07.260
Modified: 2021-10-14T18:55:24.950
Link: CVE-2021-42041
JSON object: View
Redhat Information
No data.
CWE