SB2020060230 - Open redirect in MediaWiki
Published: June 2, 2020 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Open redirect (CVE-ID: CVE-2020-10959)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
Remediation
Install update from vendor's website.