Lucene search

K
cvelistMitreCVELIST:CVE-2021-30458
HistoryApr 09, 2021 - 6:06 a.m.

CVE-2021-30458

2021-04-0906:06:04
mitre
www.cve.org
9
wikimedia parsoid
version 0.11.1
version 0.12.x
sanitization
xss

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

36.9%

An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for XSS.

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

36.9%