Medium severity6.1NVD Advisory· Published Dec 18, 2020· Updated Jun 17, 2026
CVE-2020-35478
CVE-2020-35478
Description
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <1.35.1
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- phabricator.wikimedia.org/T268938nvdExploitThird Party Advisory
- lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.htmlnvdMailing ListRelease NotesVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STT5Z4A3BCXVH3WIPICWU2FP4IPIMUPC/nvd
News mentions
0No linked articles in our index yet.