
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in the GlobalWatchlist extension in MediaWiki through version 1.36.2. The vulnerability was identified with CVE-2021-42046, where the rev-deleted-user and ntimes messages were not properly escaped, allowing users to inject HTML and JavaScript code (MITRE CVE).
The vulnerability stems from improper escaping of the rev-deleted-user and ntimes messages in the GlobalWatchlist extension. This security flaw allows for HTML and JavaScript injection, which is a form of Cross-Site Scripting (XSS) vulnerability (MITRE CVE).
The vulnerability allows attackers to inject malicious HTML and JavaScript code through the rev-deleted-user and ntimes messages, potentially leading to cross-site scripting attacks against MediaWiki users (MITRE CVE).
The vulnerability can be exploited by users who have access to the GlobalWatchlist extension in MediaWiki installations through version 1.36.2. The attack vector involves manipulation of the rev-deleted-user and ntimes messages (MITRE CVE).
The issue has been addressed in subsequent versions of MediaWiki. Users are advised to upgrade their MediaWiki installations to a version newer than 1.36.2 (MITRE CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."