PT-2023-25895 · Mediawiki+1 · Mediawiki+2
Matmarex
·
Published
2023-06-30
·
Updated
2024-08-20
·
CVE-2023-37304
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki DoubleWiki extension versions through 1.39.3
Description
An issue was discovered in the DoubleWiki extension for MediaWiki that allows XSS via the column alignment feature in includes/DoubleWiki.php.
Recommendations
For MediaWiki DoubleWiki extension versions through 1.39.3, update to a version that fixes the XSS issue in includes/DoubleWiki.php to prevent exploitation.
As a temporary workaround, consider disabling the column alignment feature in includes/DoubleWiki.php until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Doublewiki Extension
Mediawiki