An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights.
2023-12-22T02:15:42.957
2024-11-21T08:38:38.580
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mediawiki | mediawiki | < 1.35.14 | Yes |
Application | mediawiki | mediawiki | < 1.39.6 | Yes |
Application | mediawiki | mediawiki | < 1.40.2 | Yes |