mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
Several Semantic MediaWiki special pages render request-controlled error text as raw HTML. Query-error messages on Special:Ask and Special:FacetedSearch, and the invalid-subject message on Special:Browse, are derived from user-supplied input and passed to error-box output without sufficient escaping. Percent-encoded angle brackets can survive the message-encoding step and are reflected as live markup in the browser of a user who follows a crafted link. The fix applies HTML escaping to the reflected error and subject text before it is rendered.
You are affected if you are using a version that falls within the vulnerable range.
mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS) in versions 3.0.0 - 7.2.0.
Upgrade the mediawiki/semantic-media-wiki library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant