CVE-2019-19328: XSS
ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entities. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19328?
The severity of CVE-2019-19328 is categorized as a moderate risk due to the potential for HTML injection in tooltips.
How do I fix CVE-2019-19328?
To fix CVE-2019-19328, upgrade to Wikidata Query Service GUI version 0.3.6-SNAPSHOT or later.
What types of software are affected by CVE-2019-19328?
CVE-2019-19328 affects versions of the Wikimedia Wikidata Query GUI up to and including 0.3.5.
Can CVE-2019-19328 lead to a security breach?
Yes, CVE-2019-19328 can potentially lead to security breaches through malicious HTML execution in tooltips.
Is CVE-2019-19328 still a concern in the latest versions?
No, CVE-2019-19328 is no longer a concern in versions of the Wikidata Query Service GUI past 0.3.6-SNAPSHOT.