MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-45473 - Vulnerability Database
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-45473
Medium
Reference:
CVE-2021-45473
Title:
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In MediaWiki through 1.37 Wikibase item descriptions allow XSS which is triggered upon a visit to an actioninfo URL (aka a page-information sidebar).