Security readout for executives and security teams
Plain-English summary
CVE-2021-36131 is a stored cross-site scripting issue in the MediaWiki SportsTeams extension through MediaWiki 1.36. A privileged user could place HTML or JavaScript into SportsTeams data fields, causing malicious content to appear across multiple special pages and users.
Executive priority
Prioritize if SportsTeams is used on an internal or public wiki with many readers or delegated editors. The issue is not KEV-listed, but stored XSS can undermine user trust and session safety.
Technical view
The issue affects the SportsTeams extension for MediaWiki through 1.36. Several special pages failed to adequately prevent privileged users from injecting arbitrary HTML and JavaScript into data fields, creating a stored XSS condition with broad page propagation. No CVSS score or CWE is provided in the source bundle.
Likely exposure
Exposure is likely limited to MediaWiki deployments that use the SportsTeams extension through MediaWiki 1.36, especially where multiple users hold privileges to manage SportsTeams data.
Exploitation context
The sources describe a privileged-user XSS path and broad propagation, but they do not cite public exploitation, weaponized exploit availability, or CISA KEV listing. Treat this as insider, compromised-admin, or delegated-editor risk.
Researcher notes
Evidence is sparse: the CVE text identifies the affected extension, privilege requirement, and propagation risk, while the references point to Wikimedia tracking and Gerrit remediation material. No source in the bundle provides CVSS, affected package metadata, or exploitation confirmation.
Mitigation direction
- Inventory MediaWiki deployments using the SportsTeams extension through version 1.36.
- Review Wikimedia task T281196 and linked Gerrit changes for vendor remediation guidance.
- Apply the vendor-provided SportsTeams extension update or corrected code when confirmed.
- Reduce SportsTeams data-edit privileges to trusted users only.
- Review existing SportsTeams data fields for unauthorized HTML or JavaScript.
Validation and detection
- Confirm whether the SportsTeams extension is installed and enabled.
- Check MediaWiki and extension versions against the affected through-1.36 statement.
- Verify whether the linked Gerrit remediation has been applied.
- Inspect SportsTeams special pages for unexpected rendered markup or script behavior.
- Review privileged account activity around SportsTeams data changes.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-36131 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://phabricator.wikimedia.org/T281196CVE reference · x_refsource_MISC
- https://gerrit.wikimedia.org/r/q/Ic312cc9b8463c8e7c3298a661abfcff2cc2332cbCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
