CVE-2020-25815

An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
Configurations

Configuration 1

cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

Information

Published : 2020-09-27 09:15

Updated : 2022-01-01 06:39


NVD link : CVE-2020-25815

Mitre link : CVE-2020-25815

Products Affected
No products.
CWE