CVE-2020-10959Open Redirect in Mediawiki

CWE-601Open Redirect7 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 49.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateMay 24

Description

resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

Packagistmediawiki/core< 1.34.0-rc.0

Patches

🔴Vulnerability Details

2
GHSA
MediaWiki Open Redirect vulnerability2022-05-24
OSV
MediaWiki Open Redirect vulnerability2022-05-24

📋Vendor Advisories

2
Debian
CVE-2020-10959: mediawiki - resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remo...2020
Red Hat
mediawiki: user content can redirect the logout button to different URL2019-09-14

💬Community

2
Bugzilla
CVE-2020-10959 mediawiki: user content can redirect the logout button to different URL [fedora-all]2020-04-20
Bugzilla
CVE-2020-10959 mediawiki: user content can redirect the logout button to different URL2020-04-20
CVE-2020-10959 — Open Redirect in Mediawiki | cvebase