An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript via the setchange log.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-06T20:28:43

Updated: 2021-10-06T20:28:43

Reserved: 2021-10-06T00:00:00


Link: CVE-2021-42041

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-10-06T21:15:07.260

Modified: 2021-10-14T18:55:24.950


Link: CVE-2021-42041

JSON object: View

cve-icon Redhat Information

No data.

CWE