Lucene search

K
osvGoogleOSV:CVE-2022-28202
HistoryMar 30, 2022 - 6:15 a.m.

CVE-2022-28202

2022-03-3006:15:06
Google
osv.dev
5
xss
mediawiki
1.35.6
1.36.x
1.37.x
widthheight
widthheightpage
nbytes
galleries
special:revisiondelete

AI Score

5.8

Confidence

High

EPSS

0.004

Percentile

74.1%

An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.