First published: Thu Apr 22 2021(Updated: )
An issue was discovered in the PageForms extension for MediaWiki through 1.35.2. Crafted payloads for Token-related query parameters allowed for XSS on certain PageForms-managed MediaWiki pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | <=1.35.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-31551 is classified as a medium risk due to its potential for XSS attacks on MediaWiki pages.
To fix CVE-2021-31551, upgrade the PageForms extension for MediaWiki to version 1.36 or later.
CVE-2021-31551 allows for Cross-Site Scripting (XSS) attacks through crafted payloads on vulnerable MediaWiki pages.
CVE-2021-31551 affects MediaWiki versions up to and including 1.35.2.
The PageForms extension of MediaWiki is the vulnerable component in CVE-2021-31551.