MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-45474 - Vulnerability Database
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-45474
Medium
Reference:
CVE-2021-45474
Title:
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In MediaWiki through 1.37 the Special:ImportFile URI (aka FileImporter) allows XSS as demonstrated by the clientUrl parameter.