Vulnerability CVE-2021-42047


Published: 2022-09-29

Description:
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard feature enabled, users can login with a mentor account and trigger an XSS payload (such as alert) via Growthexperiments-mentor-dashboard-mentee-overview-no-js-fallback.

 References:
https://phabricator.wikimedia.org/T289063
https://www.cve.org/CVERecord?id=CVE-2021-42047
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/GrowthExperiments/+/720088

Copyright 2026, cxsecurity.com

 

Back to Top