CVE-2021-44855

MEDIUM WAF: High
CVSS 5.4 Published: 2022-12-26
CWE-79 CWE-79

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE
Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE

Affected Software

VendorProductVersion
mediawikimediawikiup to 1.35.5
mediawikimediawiki1.36.0 - 1.36.3
mediawikimediawiki1.37.0
mediawikimediawiki1.37.0
mediawikimediawiki1.37.0
mediawikimediawiki1.37.0

References

Back to CVE Database