| Name | CVE-2021-45474 |
| Description | In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
NOT-FOR-US: FileImporter MediaWiki extension
https://gerrit.wikimedia.org/r/q/Id1c8910aeac5b452fbabeddab70360765518223e
https://phabricator.wikimedia.org/T296605