Lucene search

K
cvelistMitreCVELIST:CVE-2020-35474
HistoryDec 18, 2020 - 7:30 a.m.

CVE-2020-35474

2020-12-1807:30:48
mitre
www.cve.org
6
mediawiki
xss
vulnerability
recentchanges-legend-watchlistexpiry

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

47.8%

In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

47.8%