6.1
CVSSv3

CVE-2022-34911

Published: 02/07/2022 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in MediaWiki prior to 1.35.7, 1.36.x and 1.37.x prior to 1.37.3, and 1.38.x prior to 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to "Welcome" followed by the username, the username is not escaped: SpecialCreateAccount::successfulAction() calls ::showSuccessPage() with a message as second parameter, and OutputPage::setPageTitle() uses text().

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.38.0

mediawiki mediawiki

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in restriction bypass, information leaks, cross-site scripting or denial of service For the stable distribution (bullseye), these problems have been fixed in version 1:1358-1~deb11u1 We recommend that you upgrade your mediawiki pac ...
An issue was discovered in MediaWiki before 1357, 136x and 137x before 1373, and 138x before 1381 XSS can occur in configurations that allow a JavaScript payload in a username After account creation, when it sets the page title to "Welcome" followed by the username, the username is not escaped: SpecialCreateAccount:: ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2823 mediawiki 1382-1 1383-1 Unknown Fixed phabricatorwikimediaorg/T308471 gerritwikimediaorg/r/c/mediawiki/core/+/805208 h ...