Untriaged
Sanitizer::validateAttributes data-XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Parsoid: from * before 0.16.6, 0.20.4, 0.21.1.
Affected products
Parsoid
- <0.16.6, 0.20.4, 0.21.1
MediaWiki
- <1.39.14, 1.43.4, 1.44.1
Package maintainers
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@gshipunov Grigory Shipunov <blame@oxapentane.com>
-
@astro Astro <astro@spaceboyz.net>
-
@tanneberger Tassilo Tanneberger <revol-xut@protonmail.com>