CVE-2020-10960
Summary
| CVE | CVE-2020-10960 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-03 15:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows applying an event handler to any Cascading Style Sheets (CSS) selector. There is no known way to exploit this for cross-site scripting (XSS). |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Wikitech-l] Security and maintenance release: 1.31.7 / 1.33.3 / 1.34.1 | CONFIRM | lists.wikimedia.org | Mailing List, Patch, Vendor Advisory |
| ⚓ T246602 makeCollapsible allows applying event handler to any CSS selector (CVE-2020-10960) | CONFIRM | phabricator.wikimedia.org | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 998064 PHP (Composer) Security Update for mediawiki/core (GHSA-pfm2-mqwj-ggm5)