MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later.
| Software | From | Fixed in |
|---|---|---|
| mediawiki / mediawiki | 1.33.0 | 1.35.1 |
| fedoraproject / fedora | 33 | 33.x |