Description
The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.
Published: 2020-10-28
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-20449 The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.
History

No history.

Subscriptions

Mediawiki Mediawiki
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:25:44.109Z

Reserved: 2020-10-28T00:00:00.000Z

Link: CVE-2020-27957

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-28T03:15:12.647

Modified: 2024-11-21T05:22:07.327

Link: CVE-2020-27957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses