mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
Special:FacetedSearch builds hidden card-state (cstate) inputs from request parameters and previously placed those values into HTML attributes without output-context escaping. A crafted cstate value carried in a request is reflected into the rendered search page and can inject markup that runs as live HTML in the browser of a user who views the page. This is a residual of an earlier faceted-search escaping fix that left the card-state loop exploitable. The fix escapes the card-state values before they are written into the template markup.
You are affected if you are using a version that falls within the vulnerable range and the Special:FacetedSearch interface is enabled.
mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS) in versions 4.2.0 - 7.2.0.
Upgrade the mediawiki/semantic-media-wiki library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant