VYPR
Medium severity6.1NVD Advisory· Published Oct 6, 2021· Updated Jun 17, 2026

CVE-2021-42043

CVE-2021-42043

Description

An issue was discovered in Special:MediaSearch in the MediaSearch extension in MediaWiki through 1.36.2. The suggestion text (a parameter to mediasearch-did-you-mean) was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript via the intitle: search operator within the query.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*range: <=1.36.2
    • (no CPE)range: <=1.36.2
  • osv-coords
    Range: < 1.36.3
  • MediaWiki/MediaSearchllm-fuzzy2 versions
    <=1.36.2+ 1 more
    • (no CPE)range: <=1.36.2
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.