An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-03-30T00:00:00

Updated: 2024-08-03T05:48:37.387Z

Reserved: 2022-03-30T00:00:00

Link: CVE-2022-28202

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-30T06:15:06.980

Modified: 2023-11-07T03:45:34.853

Link: CVE-2022-28202

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-03-30T00:00:00Z

Links: CVE-2022-28202 - Bugzilla