4.8
CVSSv3

CVE-2022-42985

Published: 17/11/2022 Updated: 17/11/2022
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 0

Vulnerability Summary

The ScratchLogin extension up to and including 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

scratch-wiki scratch login