Lucene search

K
osvGoogleOSV:CVE-2021-30458
HistoryApr 09, 2021 - 7:15 a.m.

CVE-2021-30458

2021-04-0907:15:16
Google
osv.dev
4

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

36.9%

An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for XSS.

CPENameOperatorVersion
parsoideq0.12.1
parsoideq0.12.0

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

36.9%