CVE-2020-35475
Summary
| CVE | CVE-2020-35475 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-18 08:15:00 UTC |
| Updated | 2023-11-07 03:21:00 UTC |
| Description | In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. (The right column with the changeable groups is not affected and is escaped correctly.) |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Application | Mediawiki | Mediawiki | All | All | All | All |
| Application | Mediawiki | Mediawiki | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-4816-1 mediawiki | DEBIAN | www.debian.org | Third Party Advisory |
| [MediaWiki-announce] Security and maintenance release: 1.31.11 / 1.35.1 | MISC | lists.wikimedia.org | Mailing List, Release Notes, Vendor Advisory |
| [SECURITY] Fedora 33 Update: mediawiki-1.35.1-1.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 33 Update: mediawiki-1.35.1-1.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| ⚓ T268917 Messages userrights-expiry-current and userrights-expiry-none can contain raw html (CVE-2020-35475) | MISC | phabricator.wikimedia.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.