mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
Semantic MediaWiki's Special:Ask table output inserts the user-controlled sep separator verbatim into the HTML that joins a table cell's values. Because the separator is not escaped, markup supplied through sep is injected into the page, and the same unsanitised table HTML is produced for the standard render and for the raw request output (request_type=raw). The reflected value executes script in the victim's browser without authentication. The fix escapes sep in all non-wiki output modes unless it is a safe line-break variant.
You are affected if you run an affected version and expose Special:Ask, which is enabled by default. The vulnerable path is a table query carrying a user-controlled sep separator, reachable through both the normal render and the raw request output (request_type=raw); no authentication is required and the payload arrives via a crafted link.
mediawiki/semantic-media-wiki is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 7.1.0.
Upgrade the mediawiki/semantic-media-wiki library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant