Description
Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRevs Extension: 1.45, 1.44, 1.43, 1.39.
Problem types
CWE-116 Improper Encoding or Escaping of Output
Product status
1.45
1.44
1.43
1.39
Credits
SomeRandomDeveloper
SomeRandomDeveloper
References
phabricator.wikimedia.org/T412068
phabricator.wikimedia.org/T412068
gerrit.wikimedia.org/...f1cbc8a519899e7f9dde508856bd4e5a5d2a
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.