CVE-2023-37256: XSS
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37256?
CVE-2023-37256 is a vulnerability in the Cargo extension for MediaWiki through 1.39.3 that allows javascript: URLs to be stored in URL fields.
How does CVE-2023-37256 impact MediaWiki?
CVE-2023-37256 allows the storage of javascript: URLs in URL fields, which can lead to the execution of malicious scripts when accessed.
What is the severity of CVE-2023-37256?
The severity of CVE-2023-37256 is medium with a CVSSv3 score of 6.1.
How can I fix the CVE-2023-37256 vulnerability?
To fix the CVE-2023-37256 vulnerability, it is recommended to update the Cargo extension for MediaWiki to a version beyond 1.39.3.
Where can I find more information about CVE-2023-37256?
More information about CVE-2023-37256 can be found at the following reference: [https://phabricator.wikimedia.org/T331311]