VulnerabilityModified
CVE-2022-28202
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2.
MEDIUM 6.1EPSS 1.21%
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mediawiki/mediawiki · fedoraproject/fedora · debian/debian linux
- Source
- cve@mitre.org
References
- https://lists.debian.org/debian-lts-announce/2022/09/msg00027.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PT4CHJKOQOVMI65TSNZRNV6FIWU7SGZD/
- https://phabricator.wikimedia.org/T297543Issue Tracking, Patch, Vendor Advisory
- https://security.gentoo.org/glsa/202305-24
- https://www.debian.org/security/2022/dsa-5246Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00027.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PT4CHJKOQOVMI65TSNZRNV6FIWU7SGZD/
- https://phabricator.wikimedia.org/T297543Issue Tracking, Patch, Vendor Advisory
- https://security.gentoo.org/glsa/202305-24
- https://www.debian.org/security/2022/dsa-5246Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.