CVE-2023-22911: XSS
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22911?
The severity of CVE-2023-22911 is medium with a CVSS score of 6.1.
What is the affected software of CVE-2023-22911?
The affected software of CVE-2023-22911 is MediaWiki versions 1.35.9, 1.36.x through 1.38.5, and 1.39.x before 1.39.1.
What is the vulnerability type of CVE-2023-22911?
The vulnerability type of CVE-2023-22911 is Cross-Site Scripting (XSS).
How does CVE-2023-22911 impact widget authors?
CVE-2023-22911 can lead to XSS because widget authors often do not expect their widget to be executed in an HTML attribute context.
Where can I find more information about CVE-2023-22911?
You can find more information about CVE-2023-22911 at the following references: [Reference 1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A/) and [Reference 2](https://phabricator.wikimedia.org/T149488).