PT-2025-28015 · Mediawiki+1 · Mediawiki+1

Published

2025-07-04

·

Updated

2025-07-04

·

CVE-2025-53482

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mediawiki - IPInfo Extension versions 1.39.X through 1.39.12 Mediawiki - IPInfo Extension versions 1.42.X through 1.42.6 Mediawiki - IPInfo Extension versions 1.43.X through 1.43.1
Description: The issue affects the Mediawiki - IPInfo Extension, allowing Cross-Site Scripting (XSS). This is due to an Improper Neutralization of Input During Web Page Generation vulnerability.
Recommendations: For versions 1.39.X through 1.39.12, update to version 1.39.13 or later. For versions 1.42.X through 1.42.6, update to version 1.42.7 or later. For versions 1.43.X through 1.43.1, update to version 1.43.2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-53482

Affected Products

Ipinfo Extension
Mediawiki