mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
Semantic MediaWiki assembles query debug output (format=debug, or the debug parameter on Special:Ask) in DebugFormatter and emits it as raw HTML. Several sinks apply no output-context encoding, so user-controlled query values reflected through the serialized ASK string, the generated SQL, or the EXPLAIN output are rendered without escaping. Targeting a text-typed property that ships on every install lets an anonymous request execute script in the victim's browser. The fix applies output-context escaping at the DebugFormatter boundary for entry values, SQL, and EXPLAIN strings.
You are affected if you run an affected version and allow query debug output (format=debug, or the debug parameter on Special:Ask), which is available by default. A crafted query targeting a text-typed property that ships on every install reflects untrusted input as raw HTML; no authentication or special rights are required.
mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 7.1.0.
Upgrade the mediawiki/semantic-media-wiki library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant