Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Untriaged
(browse all)
created 2 days, 21 hours ago
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and …

A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.

Affected products

MediaWiki
  • ==before 1.19.5 and 1.20.x before 1.20.4

Matching in nixpkgs

Package maintainers