CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
57.3%
In MediaWiki before 1.35.1, the messages userrights-expiry-current and
userrights-expiry-none can contain raw HTML. XSS can happen when a user
visits Special:UserRights but does not have rights to change all
userrights, and the table on the left side has unchangeable groups in it.
(The right column with the changeable groups is not affected and is escaped
correctly.)
launchpad.net/bugs/cve/CVE-2020-35475
lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.html
lists.wikimedia.org/pipermail/wikitech-l/2020-December/094126.html
nvd.nist.gov/vuln/detail/CVE-2020-35475
phabricator.wikimedia.org/T268917
security-tracker.debian.org/tracker/CVE-2020-35475
www.cve.org/CVERecord?id=CVE-2020-35475
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
57.3%