CVE-2021-42047 Information
Sep 30, 2022
cve
Description
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard feature enabled users can login with a mentor account and trigger an XSS payload (such as alert) via Growthexperiments-mentor-dashboard-mentee-overview-no-js-fallback.
Reference
https://phabricator.wikimedia.org/T289063 https://gerrit.wikimedia.org/r/c/mediawiki/extensions/GrowthExperiments/+/720088
Share on: