Page 7 of 270 results (0.002 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users. • https://gerrit.wikimedia.org/r/q/I993fdcae1fedb7dd543b35a477026bc727615b0a https://phabricator.wikimedia.org/T330968 •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to block a user fails after a temporary browser hang and a DBQueryDisconnectedError error message. • https://gerrit.wikimedia.org/r/q/I10a9273c542576b3f7bb38de68dcd2aa41cfb1b0 https://phabricator.wikimedia.org/T338276 •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces. • https://gerrit.wikimedia.org/r/q/Ibe5f8e25dea155bbd811a65833394c0d4b906a34 https://phabricator.wikimedia.org/T326952 •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge title attribute. This is also related to lack of escaping in wbTemplate (from resources/wikibase/templates.js) for quotes (which can be in a title attribute). • https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Wikibase/+/933649 https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Wikibase/+/933650 https://phabricator.wikimedia.org/T339111 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs. • https://phabricator.wikimedia.org/T331311 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •