First published: Fri Dec 24 2021(Updated: )
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | <=1.3.7 | |
Fedoraproject Fedora | =35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45473 has a moderate severity rating due to the potential for XSS attacks.
To fix CVE-2021-45473, you should upgrade to MediaWiki versions later than 1.37.
CVE-2021-45473 affects MediaWiki versions up to 1.37 and Fedora 35.
CVE-2021-45473 is an XSS (Cross-Site Scripting) vulnerability.
CVE-2021-45473 was disclosed in late 2021 along with the release of MediaWiki 1.37.