CVE-2025-23079: XSSes in Extension:ArticleFeedbackv5
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - ArticleFeedbackv5 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - ArticleFeedbackv5 extension: from 1.42.X before 1.42.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23079?
CVE-2025-23079 has a severity rating that indicates a significant risk of Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-23079?
To fix CVE-2025-23079, update the Mediawiki - ArticleFeedbackv5 extension to version 1.42.3 or later.
What systems are affected by CVE-2025-23079?
CVE-2025-23079 affects the Mediawiki - ArticleFeedbackv5 extension from versions 1.42.0 to 1.42.2.
What kind of vulnerability is CVE-2025-23079?
CVE-2025-23079 is classified as an Improper Neutralization of Input During Web Page Generation vulnerability, specifically allowing Cross-Site Scripting (XSS).
What impact does CVE-2025-23079 have on security?
CVE-2025-23079 can lead to unauthorized script execution in the context of a user's browser, compromising user data and session integrity.