High severity7.5NVD Advisory· Published Dec 18, 2020· Updated Jun 17, 2026
CVE-2020-35475
CVE-2020-35475
Description
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. (The right column with the changeable groups is not affected and is escaped correctly.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Range: <1.35.1
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.htmlnvdMailing ListRelease NotesVendor Advisory
- phabricator.wikimedia.org/T268917nvdIssue TrackingThird Party Advisory
- www.debian.org/security/2020/dsa-4816nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STT5Z4A3BCXVH3WIPICWU2FP4IPIMUPC/nvd
News mentions
0No linked articles in our index yet.