PT-2023-25856 · Mediawiki+1 · Googleanalyticsmetrics+1

Bawolff

·

Published

2023-06-29

·

Updated

2024-08-20

·

CVE-2023-37251

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GoogleAnalyticsMetrics extension for MediaWiki versions through 1.39.3
Description An issue was discovered in the googleanalyticstrackurl parser function, which does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.
Recommendations For versions through 1.39.3, update to a version that fixes the issue with the googleanalyticstrackurl parser function to prevent JavaScript injection through the onclick handler. As a temporary workaround, consider disabling the googleanalyticstrackurl parser function until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4877
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-37251
CVE-2023-37251

Affected Products

Alt Linux
Googleanalyticsmetrics