Security:Security Advisories and Reference:ParserFunctions: Difference between pages

(Difference between pages)
No edit summary
 
No edit summary
 
Line 1: Line 1:
{| class="wikitable" style="width:100%;"
{{BSExtensionInfobox
!Release name
|desc=Enhance parser with logical functions
!Release date
|status=stable
!Title
|developer=Tim Starling
!References
|type=MediaWiki
!Summary
|edition=BlueSpice pro, BlueSpice free, BlueSpice Farm, BlueSpice Cloud
|-
|compatible=BlueSpice
|[[Security:Security Advisories/BSSA-2022-01|BSSA-2022-01]]
|category=Rich Articles
|2022-01-31
|license=GPL v2+
|XSS attack vector in Search Center
|docu=https://www.mediawiki.org/wiki/Extension:ParserFunctions
|CVE pending
|features=The '''ParserFunctions''' extension enhances the wikitext parser with helpful functions, mostly related to logic and string-handling. Since MediaWiki 1.15, ParserFunctions has incorporated most (but not all) of the functions from the [https://www.mediawiki.org/wiki/Extension:StringFunctions StringFunctions] extension, which may be enabled or disabled.
|JavaScript in search field is reflected back to the browser.
|active=Yes
|-
}}
|[[Security:Security Advisories/BSSA-2022-02|BSSA-2022-02]]
{{wcagCheck
|2022-04-25
|wcagStatus=2-testing complete
|XSS attack vector on regular pages
|wcagCheckedfor=Web, Authoring tool
|CVE pending
|wcagTestdate=2022-08-05
|Arbitrary HTML injection through the 'title' parameter
|wcagLevel=AA
|}
|wcagSupport=supports
|wcagComments=parser functions are usually added in source edit mode.
 
Output is mostly simple text strings.
|extensionType=core
|extensionFocus=reader
}}

Latest revision as of 16:26, 5 August 2022

Extension: ParserFunctions

all extensions

Overview
Description: Enhance parser with logical functions
State: stable Dependency: BlueSpice
Developer: Tim Starling License: GPL v2+
Type: MediaWiki Category: Rich Articles
Edition: BlueSpice pro, BlueSpice free, BlueSpice Farm, BlueSpice Cloud Version: 4.1+
For more info, visit Mediawiki.

Features

The ParserFunctions extension enhances the wikitext parser with helpful functions, mostly related to logic and string-handling. Since MediaWiki 1.15, ParserFunctions has incorporated most (but not all) of the functions from the StringFunctions extension, which may be enabled or disabled.

Accessibility

Test status: 2-testing complete
Checked for: Web, Authoring tool
Last test date: 2022-08-05
WCAG level: AA
WCAG support: supports
Comments:

parser functions are usually added in source edit mode.

Output is mostly simple text strings.

Extension type: core
Extension focus: reader

Discussions