CVE-2019-12471

MEDIUM6.1EPSS 0.35%

MediaWiki Cross-site Scripting (XSS)

Published: 5/24/2022Modified: 4/28/2026
Also known as:GHSA-2rm7-xxx8-35jhDEBIAN-CVE-2019-12471

Description

Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (8)