First published: Fri Jul 02 2021(Updated: )
An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data fields. The attack could easily propagate across many pages for many users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <=1.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this XSS issue is CVE-2021-36130.
The affected software for this vulnerability is MediaWiki through version 1.36.
The severity rating of CVE-2021-36130 is medium (4.8).
The CWE ID for this vulnerability is CWE-79.
To fix the XSS issue in MediaWiki, update to a version beyond 1.36.