CVE-2023-45373: XSS
An issue was discovered in the ProofreadPage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. XSS can occur via formatNumNoSeparators.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-45373.
What is the severity of CVE-2023-45373?
The severity of CVE-2023-45373 is medium with a severity value of 6.1.
Which software versions are affected by CVE-2023-45373?
The ProofreadPage extension for MediaWiki versions 1.35.12, 1.36.x through 1.39.x, and 1.40.x before 1.40.1 are affected by CVE-2023-45373.
How does the vulnerability CVE-2023-45373 occur?
The vulnerability CVE-2023-45373 can occur via formatNumNoSeparators, allowing for cross-site scripting (XSS) attacks.
Are there any references for CVE-2023-45373?
Yes, you can find references for CVE-2023-45373 at the following links: [Link 1](https://gerrit.wikimedia.org/r/c/mediawiki/extensions/ProofreadPage/+/961262) and [Link 2](https://phabricator.wikimedia.org/T345693).