Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-08322
HistoryJan 05, 2022 - 12:00 a.m.

MediaWiki Cross-Site Scripting Vulnerability (CNVD-2022-08322)

2022-01-0500:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
mediawiki
cross-site scripting
vulnerability
clienturl
cnvd-2022-08322

EPSS

0.001

Percentile

39.1%

MediaWiki is a free and free-to-use web-based wiki engine from the US-based MediaWiki Foundation. The product can be used to deploy internal knowledge management and content management systems. A cross-site scripting vulnerability exists in MediaWiki 1.37 and earlier versions, which stems from the clientUrl field not being fully escaped and filtered for user input, and could be exploited by attackers to conduct cross-site scripting attacks.

EPSS

0.001

Percentile

39.1%