Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-35479
Description:MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later.
Test IDs: 1.3.6.1.4.1.25623.1.0.892504  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-35479
Debian Security Information: DSA-4816 (Google Search)
https://www.debian.org/security/2020/dsa-4816
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/STT5Z4A3BCXVH3WIPICWU2FP4IPIMUPC/
https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.html
https://phabricator.wikimedia.org/T268938
https://lists.debian.org/debian-lts-announce/2020/12/msg00034.html




© 1998-2025 E-Soft Inc. All rights reserved.