PT-2023-25856 · Mediawiki+1 · Googleanalyticsmetrics+1
Bawolff
·
Published
2023-06-29
·
Updated
2024-08-20
·
CVE-2023-37251
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GoogleAnalyticsMetrics extension for MediaWiki versions through 1.39.3
Description
An issue was discovered in the googleanalyticstrackurl parser function, which does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.
Recommendations
For versions through 1.39.3, update to a version that fixes the issue with the googleanalyticstrackurl parser function to prevent JavaScript injection through the onclick handler.
As a temporary workaround, consider disabling the googleanalyticstrackurl parser function until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Googleanalyticsmetrics