Lucene search

K
osvGoogleOSV:CVE-2021-45472
HistoryDec 24, 2021 - 2:15 a.m.

CVE-2021-45472

2021-12-2402:15:07
Google
osv.dev
7
mediawiki
xss
wikibase
external identifier
url
javascript url

AI Score

6

Confidence

High

EPSS

0.001

Percentile

39.1%

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

AI Score

6

Confidence

High

EPSS

0.001

Percentile

39.1%