Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28643
HistoryDec 19, 2020 - 1:34 a.m.

Cross-Site Scripting (XSS)

2020-12-1901:34:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
mediawiki
xss
vulnerability
blocklogformatter.php
remote attacker
javascript
injection

EPSS

0.001

Percentile

47.8%

MediaWik is vulnerable to cross-site scripting (XSS). A remote attacker is able to inject and execute arbitrary Javascript in a user’s browser via MediaWiki:blanknamespace in BlockLogFormatter.php.