Lucene search

K
osvGoogleOSV:CVE-2021-46150
HistoryJan 10, 2022 - 2:11 p.m.

CVE-2021-46150

2022-01-1014:11:29
Google
osv.dev
8
mediawiki
checkuserlog
xss
date mishandling

AI Score

6

Confidence

High

EPSS

0.001

Percentile

21.4%

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog allows CheckUser XSS because of date mishandling, as demonstrated by an XSS payload in MediaWiki:October.

AI Score

6

Confidence

High

EPSS

0.001

Percentile

21.4%