The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-20449 The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:25:44.109Z

Reserved: 2020-10-28T00:00:00

Link: CVE-2020-27957

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-28T03:15:12.647

Modified: 2024-11-21T05:22:07.327

Link: CVE-2020-27957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.