PT-2023-25895 · Mediawiki+1 · Mediawiki+2

Matmarex

·

Published

2023-06-30

·

Updated

2024-08-20

·

CVE-2023-37304

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki DoubleWiki extension versions through 1.39.3
Description An issue was discovered in the DoubleWiki extension for MediaWiki that allows XSS via the column alignment feature in includes/DoubleWiki.php.
Recommendations For MediaWiki DoubleWiki extension versions through 1.39.3, update to a version that fixes the XSS issue in includes/DoubleWiki.php to prevent exploitation. As a temporary workaround, consider disabling the column alignment feature in includes/DoubleWiki.php until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4877
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-37304
CVE-2023-37304

Affected Products

Alt Linux
Doublewiki Extension
Mediawiki