5.4
CVSSv3

CVE-2021-44855

Published: 26/12/2022 Updated: 21/05/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

An issue exists in MediaWiki prior to 1.35.5, 1.36.x prior to 1.36.3, and 1.37.x prior to 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki

mediawiki mediawiki 1.37.0

Vendor Advisories

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in restriction bypass, information leaks, cross-site scripting or denial of service For the stable distribution (bullseye), these problems have been fixed in version 1:1358-1~deb11u1 We recommend that you upgrade your mediawiki pac ...
DescriptionThe MITRE CVE dictionary describes this issue as: An issue was discovered in MediaWiki before 1355, 136x before 1363, and 137x before 1371 There is Blind Stored XSS via a URL to the Upload Image feature ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2823 mediawiki 1382-1 1383-1 Unknown Fixed phabricatorwikimediaorg/T293589 listswikimediaorg/hyperkitty/list/wikitech-l@lis ...