CVE-2023-37254: XSS
Published Jun 29, 2023
·Updated
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. XSS can occur in Special:CargoQuery via a crafted page item when using the default format.
Affected Software
1 affected component
MediaWiki MediaWiki<=1.39.3
Event History
Jun 29, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-37254.
2
What is the severity rating of CVE-2023-37254?
CVE-2023-37254 has a severity rating of medium (6.1).
3
How does the vulnerability CVE-2023-37254 occur?
CVE-2023-37254 occurs in the Cargo extension for MediaWiki through version 1.39.3 when using the default format in Special:CargoQuery via a crafted page item.
4
What is the affected software of CVE-2023-37254?
The affected software of CVE-2023-37254 is MediaWiki through version 1.39.3.
5
Is there a fix available for CVE-2023-37254?
Yes, a fix for CVE-2023-37254 is available. Please refer to the provided reference link for more information.