CVE-2021-30157: XSS
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter- label messages are output in HTML unescaped, leading to XSS.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-30157?
CVE-2021-30157 has been identified as a moderate severity vulnerability associated with XSS due to unescaped HTML output.
How do I fix CVE-2021-30157?
To fix CVE-2021-30157, upgrade your MediaWiki installation to a version equal to or greater than 1.31.12 or 1.35.2.
Which versions of MediaWiki are affected by CVE-2021-30157?
MediaWiki versions before 1.31.12 and from 1.32.0 to 1.35.1 are affected by CVE-2021-30157.
What type of vulnerability is CVE-2021-30157?
CVE-2021-30157 is classified as a cross-site scripting (XSS) vulnerability.
Is there a specific operating system impacted by CVE-2021-30157?
Yes, CVE-2021-30157 affects MediaWiki installations on Debian and Fedora operating systems.