mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
Semantic MediaWiki's Special:SearchByProperty reflects the user-supplied property and value request parameters back into the rendered form field, validation error messages, and result heading. These values are emitted without sufficient output-context encoding, so markup supplied through property or value becomes executable HTML in the response. A crafted link reflects the payload and runs script in the victim's browser without authentication. The fix escapes the form value and derived error messages before they are rendered into HTML.
You are affected if you run an affected version with Special:SearchByProperty reachable, which is enabled by default. A crafted link supplying property/value reflects untrusted input into the rendered form field and error text; exploitation requires no authentication or special permissions.
mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 7.1.0.
Upgrade the mediawiki/semantic-media-wiki library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant