CVE-2023-36675: XSS
An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mediawikito a version that resolves this vulnerability.Fixed in 1:1.31.16-1+deb10u2Fixed in 1:1.31.16-1+deb10u6Fixed in 1:1.35.11-1~deb11u1Fixed in 1:1.35.13-1~deb11u1Fixed in 1:1.39.4-1~deb12u1Fixed in 1:1.39.5-1~deb12u1Fixed in 1:1.39.5-1
Event History
Frequently Asked Questions
What is CVE-2023-36675?
CVE-2023-36675 is a vulnerability in MediaWiki that allows for XSS (cross-site scripting) attacks in the partial blocks feature.
How severe is CVE-2023-36675?
CVE-2023-36675 has a severity rating of 6.1, which is considered medium.
What versions of MediaWiki are affected by CVE-2023-36675?
CVE-2023-36675 affects MediaWiki versions 1.31.16-1+deb10u2, 1.31.16-1+deb10u6, 1.35.11-1~deb11u1, 1.39.4-1~deb12u1, and 1.39.4-2.
How can I fix CVE-2023-36675?
To fix CVE-2023-36675, you should upgrade to MediaWiki version 1.35.11 or apply the recommended patches provided by the vendor.
Where can I find more information about CVE-2023-36675?
More information about CVE-2023-36675 can be found on the Gerrit Wikimedia, Phabricator Wikimedia, and the Debian Security Tracker websites.