GHSA-5pqx-77vf-85rw

Suggest an improvement
Source
https://github.com/advisories/GHSA-5pqx-77vf-85rw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5pqx-77vf-85rw/GHSA-5pqx-77vf-85rw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5pqx-77vf-85rw
Aliases
Published
2022-05-24T17:47:02Z
Modified
2024-06-07T22:29:02.090533Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Wikimedia Parsoid vulnerable to Cross-site Scripting (XSS)
Details

An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for XSS.

Database specific
{
    "nvd_published_at": "2021-04-09T07:15:00Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-06-07T22:12:19Z"
}
References

Affected packages

Packagist / wikimedia/parsoid

Package

Name
wikimedia/parsoid
Purl
pkg:composer/wikimedia/parsoid

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.12
Fixed
0.12.2

Affected versions

v0.*

v0.12.0-a1
v0.12.0-a2
v0.12.0-a3
v0.12.0-a4
v0.12.0-a5
v0.12.0-a6
v0.12.0-a7
v0.12.0-a8
v0.12.0-a9
v0.12.0-a10
v0.12.0-a11
v0.12.0-a12
v0.12.0-a13
v0.12.0-a14
v0.12.0-a15
v0.12.0-a16
v0.12.0-a17
v0.12.0-a18
v0.12.0-a19
v0.12.0-a20
v0.12.0-a21
v0.12.0-a22
v0.12.0-a23
v0.12.0
v0.12.1

Packagist / wikimedia/parsoid

Package

Name
wikimedia/parsoid
Purl
pkg:composer/wikimedia/parsoid

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.11.1

Affected versions

v0.*

v0.11.0