CVE-2021-42048
Summary
| CVE | CVE-2021-42048 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-29 03:15:00 UTC |
| Updated | 2022-09-30 16:42:00 UTC |
| Description | An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ⚓ T289064 Newcomer homepage Impact module: Permanent XSS exploitable by admins for new accounts (CVE-2021-42048) | MISC | phabricator.wikimedia.org | |
| cve-website | MISC | www.cve.org | |
| gerrit.wikimedia.org/r/q/Iaa90a8976834d70caad592e9d1b18510318db537 | MISC | gerrit.wikimedia.org | |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.