First published: Fri Jan 20 2023(Updated: )
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There is XSS in Wikibase date formatting via wikibase-time-precision-* fields. This allows JavaScript execution by staff/admin users who do not intentionally have the editsitejs capability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <1.35.9 | |
MediaWiki MediaWiki | >=1.36.0<1.38.5 | |
MediaWiki MediaWiki | =1.39.0 | |
MediaWiki MediaWiki | =1.39.0-rc0 | |
MediaWiki MediaWiki | =1.39.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22910 is a vulnerability in MediaWiki that allows for XSS attacks via wikibase-time-precision-* fields.
CVE-2023-22910 has a severity rating of 5.4, which is considered medium.
CVE-2023-22910 affects MediaWiki versions before 1.35.9, between 1.36.0 and 1.38.5, and 1.39.0 and 1.39.1.
To fix CVE-2023-22910, it is recommended to upgrade to MediaWiki version 1.35.9, 1.38.5, or 1.39.1.
More information about CVE-2023-22910 can be found at the following reference: [link](https://phabricator.wikimedia.org/T323592).