CVE-2020-27620
22.10.2020, 04:15
The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.
Vendor | Product | Version |
---|---|---|
mediawiki | skin\ | 𝑥 ≤ 1.35.0 |
𝑥
= Vulnerable software versions
References