Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for XSS.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MediaWiki Parsoid 跨站脚本漏洞
Vulnerability Description
MediaWiki Parsoid是MediaWiki社区开源的一个应用程序。提供一个一个允许在Wikitext和HTML之间来回转换的库。 Wikimedia Parsoid 0.11.1之前版本及0.12.x系列0.12.2之前版本存在跨站脚本漏洞,攻击者可利用该漏洞可以发送精心制作的wikitext, Utils WTUtils.php将通过使用<meta>标记进行转换,绕过验证。
CVSS Information
N/A
Vulnerability Type
N/A