CVE-2021-30458
09.04.2021, 07:15
An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for XSS.
| Vendor | Product | Version |
|---|---|---|
| wikimedia | parsoid | 𝑥 < 0.11.1 |
| wikimedia | parsoid | 0.12.0 ≤ 𝑥 < 0.12.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases