CVE-2022-21710
Cross-site Scripting in ShortDescription extension
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS can be triggered on any page or the page with the action=info parameter, which displays the shortdesc property. This is achieved using the wikitext `{{SHORTDESC:<img src=x onerror=alert()>}}`. This issue has a patch in version 2.3.4.
ShortDescription es una extensión de MediaWiki que proporciona soporte local para descripciones cortas. Se presenta una vulnerabilidad de tipo cross-site scripting (XSS) en versiones anteriores a 2.3.4. En un wiki que tenga la ShortDescription habilitada, un ataque de tipo XSS puede ser desencadenado en cualquier página o en la página con el parámetro action=info, que muestra la propiedad shortdesc. Esto es conseguido usando el wikitext "{SHORTDESC:<img src=x onerror=alert()>}}". Este problema presenta un parche en la versión 2.3.4
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-16 CVE Reserved
- 2022-01-24 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/StarCitizenTools/mediawiki-extensions-ShortDescription/security/advisories/GHSA-mgcp-qw2r-6832 | 2024-08-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mediawiki Search vendor "Mediawiki" | Shortdescription Search vendor "Mediawiki" for product "Shortdescription" | < 2.3.4 Search vendor "Mediawiki" for product "Shortdescription" and version " < 2.3.4" | mediawiki |
Affected
|