First published: Mon Jun 26 2023(Updated: )
An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | 1:1.31.16-1+deb10u2 1:1.31.16-1+deb10u6 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.4-1~deb12u1 1:1.39.5-1~deb12u1 1:1.39.5-1 | |
MediaWiki MediaWiki | <1.35.11 | |
MediaWiki MediaWiki | >=1.36.0<1.38.7 | |
MediaWiki MediaWiki | >=1.39.0<1.39.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36675 is a vulnerability in MediaWiki that allows for XSS (cross-site scripting) attacks in the partial blocks feature.
CVE-2023-36675 has a severity rating of 6.1, which is considered medium.
CVE-2023-36675 affects MediaWiki versions 1.31.16-1+deb10u2, 1.31.16-1+deb10u6, 1.35.11-1~deb11u1, 1.39.4-1~deb12u1, and 1.39.4-2.
To fix CVE-2023-36675, you should upgrade to MediaWiki version 1.35.11 or apply the recommended patches provided by the vendor.
More information about CVE-2023-36675 can be found on the Gerrit Wikimedia, Phabricator Wikimedia, and the Debian Security Tracker websites.