First published: Tue Jan 10 2023(Updated: )
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <1.35.9 | |
MediaWiki MediaWiki | >=1.36.0<1.38.5 | |
MediaWiki MediaWiki | =1.39.0 | |
MediaWiki MediaWiki | =1.39.0-rc0 | |
MediaWiki MediaWiki | =1.39.0-rc1 | |
Fedoraproject Fedora | =37 | |
<1.35.9 | ||
>=1.36.0<1.38.5 | ||
=1.39.0 | ||
=1.39.0-rc0 | ||
=1.39.0-rc1 | ||
=37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-22911 is medium with a CVSS score of 6.1.
The affected software of CVE-2023-22911 is MediaWiki versions 1.35.9, 1.36.x through 1.38.5, and 1.39.x before 1.39.1.
The vulnerability type of CVE-2023-22911 is Cross-Site Scripting (XSS).
CVE-2023-22911 can lead to XSS because widget authors often do not expect their widget to be executed in an HTML attribute context.
You can find more information about CVE-2023-22911 at the following references: [Reference 1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A/) and [Reference 2](https://phabricator.wikimedia.org/T149488).