CVE-2020-15179
HTML Injection in ScratchSig
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The ScratchSig extension for MediaWiki before version 1.0.1 allows stored Cross-Site Scripting. Using <script> tag inside <scratchsig> tag, attackers with edit permission can execute scripts on visitors' browser. With MediaWiki JavaScript API, this can potentially lead to privilege escalation and/or account takeover. This has been patched in release 1.0.1. This has already been deployed to all Scratch Wikis. No workarounds exist other than disabling the extension completely.
La extensión ScratchSig para MediaWiki versiones anteriores a 1.0.1, permite un ataque de tipo Cross-Site Scripting almacenado. Usando la etiqueta (script) dentro de la etiqueta (scratchsig), los atacantes con permiso de edición pueden ejecutar scripts en el navegador de los visitantes. Con MediaWiki JavaScript API, esto puede conllevar potencialmente a una escalada de privilegios y/o la toma de control de la cuenta. Esto ha sido parcheado en la versión 1.0.1. Esto ya ha sido implementado en todas las Scratch Wikis. No existen soluciones alternativas que no sean deshabilitar la extensión por completo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-06-25 CVE Reserved
- 2020-09-15 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/InternationalScratchWiki/wiki-scratchsig/security/advisories/GHSA-gp9v-pg9f-vmp6 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/InternationalScratchWiki/wiki-scratchsig/commit/4160a39a20eebeb63a59eb7597a91b961eca6388 | 2020-09-22 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Scratch-wiki Search vendor "Scratch-wiki" | Scratchsig Search vendor "Scratch-wiki" for product "Scratchsig" | < 1.0.1 Search vendor "Scratch-wiki" for product "Scratchsig" and version " < 1.0.1" | mediawiki |
Affected
|