High severity8.0NVD Advisory· Published Sep 15, 2020· Updated Jun 17, 2026
CVE-2020-15179
CVE-2020-15179
Description
The ScratchSig extension for MediaWiki before version 1.0.1 allows stored Cross-Site Scripting. Using tag inside tag, attackers with edit permission can execute scripts on visitors' browser. With MediaWiki JavaScript API, this can potentially lead to privilege escalation and/or account takeover. This has been patched in release 1.0.1. This has already been deployed to all Scratch Wikis. No workarounds exist other than disabling the extension completely.
Affected products
3- Range: < 1.0.1
- Range: <1.0.1
Patches
Vulnerability mechanics
References
2- github.com/InternationalScratchWiki/wiki-scratchsig/commit/4160a39a20eebeb63a59eb7597a91b961eca6388nvdPatchThird Party Advisory
- github.com/InternationalScratchWiki/wiki-scratchsig/security/advisories/GHSA-gp9v-pg9f-vmp6nvdThird Party Advisory
News mentions
0No linked articles in our index yet.