CVE-2020-9382
Published Feb 24, 2020An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by thi…
Vendor/product archive
2 CVEs tagged to widgets_project / widgets — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by thi…
Cross-site scripting (XSS) vulnerability in the Widgets extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors involving base64 encoded…