CVE-2021-44855: XSS
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44855?
CVE-2021-44855 is an issue in MediaWiki before version 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1 that allows Blind Stored XSS via a URL to the Upload Image feature.
How severe is CVE-2021-44855?
CVE-2021-44855 has a severity level of medium with a CVSS score of 5.4.
How can I fix CVE-2021-44855?
To fix CVE-2021-44855, it is recommended to upgrade MediaWiki to version 1.35.5, 1.36.3, or 1.37.1 depending on your current installation.
Where can I find more information about CVE-2021-44855?
You can find more information about CVE-2021-44855 in the following references: [1] [2] [3].
What is the Common Weakness Enumeration (CWE) for CVE-2021-44855?
The Common Weakness Enumeration (CWE) for CVE-2021-44855 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).