Medium severity6.1NVD Advisory· Published Sep 27, 2020· Updated Jun 17, 2026
CVE-2020-25815
CVE-2020-25815
Description
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mediawiki/corePackagist | >= 1.32.0, < 1.34.3 | 1.34.3 |
mediawiki/corePackagist | >= 1.35.0-rc.0, < 1.35.0 | 1.35.0 |
Affected products
4- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- osv-coords2 versions
>= 1.32.0, < 1.34.4+ 1 more
- (no CPE)range: >= 1.32.0, < 1.34.4
- (no CPE)range: >= 1.32.0, < 1.34.3
Patches
Vulnerability mechanics
References
9- gerrit.wikimedia.org/g/mediawiki/core/+/ec76e14be658187544f07c1a249a047e1a75eaf8/includes/logging/LogEventsList.phpnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-2f58-vf6g-6p8xghsaADVISORY
- lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.htmlnvdMailing ListVendor AdvisoryWEB
- lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.htmlnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-25815ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2020-25815.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6ghsaWEB
- phabricator.wikimedia.org/T256171ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6/nvd
News mentions
0No linked articles in our index yet.