The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true).
References
Link | Resource |
---|---|
https://phabricator.wikimedia.org/T307028 | Exploit Issue Tracking Third Party Advisory |
https://gerrit.wikimedia.org/r/c/787807 | Patch Third Party Advisory |
Configurations
Information
Published : 2022-05-01 22:15
Updated : 2022-05-09 10:08
NVD link : CVE-2022-29969
Mitre link : CVE-2022-29969
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
mediawiki
- rss_for_mediawiki