296,147
Total vulnerabilities in the database
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard feature enabled, users can login with a mentor account and trigger an XSS payload (such as alert) via Growthexperiments-mentor-dashboard-mentee-overview-no-js-fallback.
Software | From | Fixed in |
---|---|---|
mediawiki / mediawiki | - | 1.36.2.x |