CVE-2021-42041

MEDIUM

MediaWiki < 1.36.2 - Stored Cross-Site Scripting via CentralAuth Rightsnone Message

Title source: llm
STIX 2.1

Description

An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript via the setchange log.

References (2)

Core 2
Core References
Exploit, Patch, Vendor Advisory x_refsource_misc
https://phabricator.wikimedia.org/T291696

Scores

CVSS v3 6.1
EPSS 0.0051
EPSS Percentile 66.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
mediawiki/mediawiki < 1.36.2
Published Oct 06, 2021
Tracked Since Feb 18, 2026