Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog allows CheckUser XSS because of date mishandling, as demonstrated by an XSS payload in MediaWiki:October.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MediaWiki 跨站脚本漏洞
Vulnerability Description
MediaWiki是美国维基媒体(MediaWiki)基金会的一套自由免费的基于网络的Wiki引擎。该产品可用于部署内部的知识管理和内容管理系统。WikibaseMediaInfo是使用在其中的一个用于处理多媒体文件的结构化数据的扩展程序。 MediaWiki 中存在跨站脚本漏洞,该漏洞源于产品的MediaWiki:October函数未对输入数据做有效检查,攻击者可通过该漏洞执行客户端代码。
CVSS Information
N/A
Vulnerability Type
N/A