Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-30458
HistoryApr 09, 2021 - 7:15 a.m.

Cross site scripting

2021-04-0907:15:00
PRIOn knowledge base
www.prio-n.com
9

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.9%

An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for XSS.

CPENameOperatorVersion
parsoidge0.12.0
parsoidlt0.12.2
parsoidlt0.11.1

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.9%