Description
In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows applying an event handler to any Cascading Style Sheets (CSS) selector. There is no known way to exploit this for cross-site scripting (XSS).
Published: 2020-04-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-4651-1 mediawiki security update
EUVD EUVD EUVD-2022-4752 In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows applying an event handler to any Cascading Style Sheets (CSS) selector. There is no known way to exploit this for cross-site scripting (XSS).
Github GHSA Github GHSA GHSA-pfm2-mqwj-ggm5 MediaWiki makeCollapsible allows applying event handler to any CSS selector
History

No history.

Subscriptions

Mediawiki Mediawiki
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T11:21:14.164Z

Reserved: 2020-03-25T00:00:00.000Z

Link: CVE-2020-10960

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-03T15:15:14.497

Modified: 2024-11-21T04:56:27.533

Link: CVE-2020-10960

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-03-02T00:00:00Z

Links: CVE-2020-10960 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses