Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vulnerability is associated with program files includes/parser/Sanitizer.Php, src/Core/Sanitizer.Php.
This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1; Parsoid: from * before 0.16.6, 0.20.4, 0.21.1.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.39.14"
},
{
"introduced": "1.39.15"
},
{
"fixed": "1.43.4"
},
{
"introduced": "1.43.5"
},
{
"fixed": "1.44.1"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "0.16.6"
},
{
"introduced": "0"
},
{
"fixed": "0.20.4"
},
{
"introduced": "0"
},
{
"fixed": "0.21.1"
}
]
}