Lucene search

K
osvGoogleOSV:CVE-2021-45474
HistoryDec 24, 2021 - 2:15 a.m.

CVE-2021-45474

2021-12-2402:15:07
Google
osv.dev
9
mediawiki security
xss vulnerability
fileimporteruri

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

39.1%

In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

39.1%