Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28642
HistoryDec 19, 2020 - 1:34 a.m.

Cross-site Scripting (XSS)

2020-12-1901:34:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
cross-site scripting
mediawiki
special:userrights
vulnerability
userrights

EPSS

0.002

Percentile

57.3%

mediawiki is vulnerable to cross-site scripting (XSS). The vulnerability exists when a user visits Special:UserRights and does not have rights to change all userrights, and the table on the left side has unchangeable groups in it.