PT-2023-18771 · Mediawiki+1 · Mediawiki+1

Bawolff

+1

·

Published

2023-01-10

·

Updated

2025-04-07

·

CVE-2023-22911

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.9 MediaWiki versions 1.36.x through 1.38.x before 1.38.5 MediaWiki versions 1.39.x before 1.39.1
Description An issue in MediaWiki allows for XSS due to E-Widgets performing widget replacement in HTML attributes. This can lead to security issues because widget authors often do not expect their widgets to be executed in an HTML attribute context.
Recommendations For MediaWiki versions prior to 1.35.9, update to version 1.35.9 or later. For MediaWiki versions 1.36.x through 1.38.x before 1.38.5, update to version 1.38.5 or later. For MediaWiki versions 1.39.x before 1.39.1, update to version 1.39.1 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4877
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-22911
CVE-2023-22911
MGASA-2023-0204

Affected Products

Alt Linux
Mediawiki