CVE-2022-34491

CVE-2022-34491

In the RSS extension for MediaWiki through 1.38.1, when the $wgRSSAllowLinkTag config variable was set to true, and a new RSS feed was created with certain XSS payloads within its description tags and added to the $wgRSSUrlWhitelist config variable, stored XSS could occur via MediaWiki’s template system whenever that feed was loaded via the rss document tag.

Source: CVE-2022-34491

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다