Lucene search

K
cveMitreCVE-2022-34911
HistoryJul 02, 2022 - 8:15 p.m.

CVE-2022-34911

2022-07-0220:15:08
CWE-79
mitre
web.nvd.nist.gov
62
8
cve-2022-34911
mediawiki
xss
1.35.7
1.36.x
1.37.x
1.38.x
security vulnerability
javascript payload
username
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.003

Percentile

68.7%

An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to “Welcome” followed by the username, the username is not escaped: SpecialCreateAccount::successfulAction() calls ::showSuccessPage() with a message as second parameter, and OutputPage::setPageTitle() uses text().

Affected configurations

Nvd
Node
mediawikimediawikiRange<1.35.7
OR
mediawikimediawikiRange1.36.01.37.3
OR
mediawikimediawikiMatch1.38.0-
OR
mediawikimediawikiMatch1.38.0rc0
OR
mediawikimediawikiMatch1.38.0rc1
Node
fedoraprojectfedoraMatch36
OR
fedoraprojectfedoraMatch37
VendorProductVersionCPE
mediawikimediawiki*cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
mediawikimediawiki1.38.0cpe:2.3:a:mediawiki:mediawiki:1.38.0:-:*:*:*:*:*:*
mediawikimediawiki1.38.0cpe:2.3:a:mediawiki:mediawiki:1.38.0:rc0:*:*:*:*:*:*
mediawikimediawiki1.38.0cpe:2.3:a:mediawiki:mediawiki:1.38.0:rc1:*:*:*:*:*:*
fedoraprojectfedora36cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
fedoraprojectfedora37cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.003

Percentile

68.7%