CVE-2020-27957
The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certa
The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.
MEDIUM · CVSS 5.4
EPSS 0.00315
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0