PT-2025-4810 · Mediawiki · Openbadges Extension+1

Blankeclair

·

Published

2025-01-14

·

Updated

2025-01-18

·

CVE-2025-23080

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mediawiki - OpenBadges Extension versions 1.39.X through 1.39.10 Mediawiki - OpenBadges Extension versions 1.41.X through 1.41.2 Mediawiki - OpenBadges Extension versions 1.42.X through 1.42.1
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-Site Scripting (XSS). This allows for Cross-Site Scripting (XSS) in the Mediawiki - OpenBadges Extension.
Recommendations For versions 1.39.X through 1.39.10, update to version 1.39.11 or later. For versions 1.41.X through 1.41.2, update to version 1.41.3 or later. For versions 1.42.X through 1.42.1, update to version 1.42.2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-23080

Affected Products

Mediawiki
Openbadges Extension