Lucene search

K
osvGoogleOSV:CVE-2020-35474
HistoryDec 18, 2020 - 8:15 a.m.

CVE-2020-35474

2020-12-1808:15:15
Google
osv.dev
9
mediawiki
xss
vulnerability
html
recent changes

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

47.8%

In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

47.8%