First published: Wed Oct 06 2021(Updated: )
An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The growthexperiments-edit-config-error-invalid-title MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | <=1.36.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42042 has been classified as a high severity vulnerability due to the potential for HTML and JavaScript injection.
To fix CVE-2021-42042, upgrade MediaWiki to version 1.36.3 or later where the vulnerability has been addressed.
The impact of CVE-2021-42042 includes potential unauthorized execution of scripts, which could compromise the integrity and security of the MediaWiki installation.
CVE-2021-42042 affects all MediaWiki installations using version 1.36.2 or earlier.
CVE-2021-42042 does not directly lead to remote code execution, but it allows script injection which can lead to various attacks.