Page 6 of 283 results (0.003 seconds)

CVSS: 5.3EPSS: 0%CPEs: 3EXPL: 0

An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. During item merging, ItemMergeInteractor does not have an edit filter running (e.g., AbuseFilter). Se descubrió un problema en la extensión de Wikibase para MediaWiki antes de 1.35.12, 1.36.x hasta 1.39.x antes de 1.39.5 y 1.40.x antes de 1.40.1. Durante la combinación de elementos, ItemMergeInteractor no tiene ningún filtro de edición en ejecución (por ejemplo, AbuseFilter). • https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Wikibase/+/961264 https://phabricator.wikimedia.org/T345064 • CWE-693: Protection Mechanism Failure •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

An issue was discovered in the ProofreadPage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. XSS can occur via formatNumNoSeparators. Se descubrió un problema en la extensión ProofreadPage para MediaWiki anterior a 1.35.12, 1.36.x a 1.39.x anterior a 1.39.5 y 1.40.x anterior a 1.40.1. XSS puede ocurrir a través de formatNumNoSeparators. • https://gerrit.wikimedia.org/r/c/mediawiki/extensions/ProofreadPage/+/961262 https://phabricator.wikimedia.org/T345693 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 4EXPL: 0

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax. Se descubrió un problema en MediaWiki antes de 1.35.11, 1.36.x hasta 1.38.x antes de 1.38.7, 1.39.x antes de 1.39.4 y 1.40.x antes de 1.40.1. Es posible omitir la Lista de Imágenes Incorrectas (también conocida como badFile) utilizando el parámetro de thumb (también conocido como Manualthumb) de la Sintaxis del Archivo. • https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6 https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5 https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O https://phabricator.wikimedia.org/T335612 • CWE-20: Improper Input Validation •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge title attribute. This is also related to lack of escaping in wbTemplate (from resources/wikibase/templates.js) for quotes (which can be in a title attribute). • https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Wikibase/+/933649 https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Wikibase/+/933650 https://phabricator.wikimedia.org/T339111 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in the DoubleWiki extension for MediaWiki through 1.39.3. includes/DoubleWiki.php allows XSS via the column alignment feature. • https://gerrit.wikimedia.org/r/c/mediawiki/extensions/DoubleWiki/+/932825 https://phabricator.wikimedia.org/T323651 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •