PT-2023-18771 · Mediawiki+1 · Mediawiki+1

Bawolff

+1

·

Publicado

2023-01-10

·

Atualizado

2025-04-07

·

CVE-2023-22911

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.9 MediaWiki versions 1.36.x through 1.38.x before 1.38.5 MediaWiki versions 1.39.x before 1.39.1
Description An issue in MediaWiki allows for XSS due to E-Widgets performing widget replacement in HTML attributes. This can lead to security issues because widget authors often do not expect their widgets to be executed in an HTML attribute context.
Recommendations For MediaWiki versions prior to 1.35.9, update to version 1.35.9 or later. For MediaWiki versions 1.36.x through 1.38.x before 1.38.5, update to version 1.38.5 or later. For MediaWiki versions 1.39.x before 1.39.1, update to version 1.39.1 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-4877
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-22911
CVE-2023-22911
MGASA-2023-0204

Produtos afetados

Alt Linux
Mediawiki