In the non-default configuration where $wgAdvancedSearchHighlighting
is set to true, there is an XSS vulnerability as HTML tags are
not properly escaped if the tag spans multiple search results
Issue introduced in
|
||
|---|---|---|
| .. | ||
| AugmentPageProps.php | ||
| DummySearchIndexFieldDefinition.php | ||
| NullIndexField.php | ||
| ParserOutputSearchDataExtractor.php | ||
| PerRowAugmentor.php | ||
| ResultAugmentor.php | ||
| ResultSetAugmentor.php | ||
| SearchDatabase.php | ||
| SearchEngine.php | ||
| SearchEngineConfig.php | ||
| SearchEngineFactory.php | ||
| SearchExactMatchRescorer.php | ||
| SearchHighlighter.php | ||
| SearchIndexField.php | ||
| SearchIndexFieldDefinition.php | ||
| SearchMssql.php | ||
| SearchMySQL.php | ||
| SearchNearMatcher.php | ||
| SearchNearMatchResultSet.php | ||
| SearchOracle.php | ||
| SearchPostgres.php | ||
| SearchResult.php | ||
| SearchResultSet.php | ||
| SearchSqlite.php | ||
| SearchSuggestion.php | ||
| SearchSuggestionSet.php | ||
| SqlSearchResultSet.php | ||