← Back to CVE List

CVE-2021-30458

Published: 2021-04-09T07:15Z
Last Modified: 2024-11-21T06:03Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for XSS. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt