CVE-2021-30458 log

Source
Severity Medium
Remote Yes
Type Cross-site scripting
Description
An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for cross-site scripting (XSS).
Group Package Affected Fixed Severity Status Ticket
AVG-1775 mediawiki 1.35.1-2 1.35.2-1 Medium Fixed
References
https://phabricator.wikimedia.org/T279451
https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/services/parsoid/+/15169a678f9f468ff6465035a32f28e8ec82003f%5E%21/