In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows applying an event handler to any Cascading Style Sheets (CSS) selector. There is no known way to exploit this for cross-site scripting (XSS).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-04-03T14:13:52

Updated: 2024-08-04T11:21:14.164Z

Reserved: 2020-03-25T00:00:00

Link: CVE-2020-10960

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-04-03T15:15:14.497

Modified: 2021-07-21T11:39:23.747

Link: CVE-2020-10960

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-03-02T00:00:00Z

Links: CVE-2020-10960 - Bugzilla