The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-05-02T04:18:27
Updated: 2024-08-03T06:40:46.271Z
Reserved: 2022-05-02T00:00:00
Link: CVE-2022-29969
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-05-02T05:15:06.680
Modified: 2022-05-09T17:08:45.153
Link: CVE-2022-29969
Redhat