CVE-2023-22910: XSS
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There is XSS in Wikibase date formatting via wikibase-time-precision- fields. This allows JavaScript execution by staff/admin users who do not intentionally have the editsitejs capability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-22910?
CVE-2023-22910 is a vulnerability in MediaWiki that allows for XSS attacks via wikibase-time-precision-* fields.
How severe is CVE-2023-22910?
CVE-2023-22910 has a severity rating of 5.4, which is considered medium.
Which versions of MediaWiki are affected by CVE-2023-22910?
CVE-2023-22910 affects MediaWiki versions before 1.35.9, between 1.36.0 and 1.38.5, and 1.39.0 and 1.39.1.
How can I fix CVE-2023-22910?
To fix CVE-2023-22910, it is recommended to upgrade to MediaWiki version 1.35.9, 1.38.5, or 1.39.1.
Where can I find more information about CVE-2023-22910?
More information about CVE-2023-22910 can be found at the following reference: [link](https://phabricator.wikimedia.org/T323592).