{"id":"GHSA-4vr7-m8p8-434h","summary":"MediaWiki Cross-site Scripting (XSS) vulnerability","details":"In MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an \u003ca\u003e tag (or it does not have a href attribute, or it's empty, etc.). The actual result is that the object contains an \u003ca href =\"javascript... that executes when clicked.","aliases":["BIT-mediawiki-2020-25814","CVE-2020-25814"],"modified":"2024-05-17T22:11:51.909230Z","published":"2022-05-24T17:29:42Z","database_specific":{"github_reviewed_at":"2024-05-17T21:56:21Z","nvd_published_at":"2020-09-27T21:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25814"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2020-25814.yaml"},{"type":"PACKAGE","url":"https://github.com/wikimedia/mediawiki"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6"},{"type":"WEB","url":"https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.html"},{"type":"WEB","url":"https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.html"},{"type":"WEB","url":"https://phabricator.wikimedia.org/T86738"},{"type":"WEB","url":"https://www.mediawiki.org/wiki/ResourceLoader/Core_modules#mediawiki.jqueryMsg"}],"affected":[{"package":{"name":"mediawiki/core","ecosystem":"Packagist","purl":"pkg:composer/mediawiki/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.31.0"},{"fixed":"1.31.9"}]}],"versions":["1.31.0","1.31.1","1.31.2","1.31.3","1.31.4","1.31.5","1.31.6","1.31.7","1.31.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4vr7-m8p8-434h/GHSA-4vr7-m8p8-434h.json"}},{"package":{"name":"mediawiki/core","ecosystem":"Packagist","purl":"pkg:composer/mediawiki/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.32.0"},{"fixed":"1.34.3"}]}],"versions":["1.32.0","1.32.1","1.32.2","1.32.3","1.32.4","1.32.5","1.32.6","1.33.0","1.33.0-rc.0","1.33.1","1.33.2","1.33.3","1.33.4","1.34.0","1.34.0-rc.0","1.34.0-rc.1","1.34.1","1.34.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4vr7-m8p8-434h/GHSA-4vr7-m8p8-434h.json"}},{"package":{"name":"mediawiki/core","ecosystem":"Packagist","purl":"pkg:composer/mediawiki/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.35.0-rc.0"},{"fixed":"1.35.0"}]}],"versions":["1.35.0-rc.0","1.35.0-rc.1","1.35.0-rc.2","1.35.0-rc.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4vr7-m8p8-434h/GHSA-4vr7-m8p8-434h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}