First published: Tue Jan 14 2025(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - OpenBadges Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - OpenBadges Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.
Credit: c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki - OpenBadges Extension | >1.39.11>1.41.3>1.42.2>=1.39.0<1.39.11>=1.41.0<1.41.3>=1.42.0<1.42.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23080 is classified as a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2025-23080, upgrade the Mediawiki - OpenBadges Extension to version 1.39.11 or later, or to any version above 1.41.3 or 1.42.2.
CVE-2025-23080 affects the Mediawiki - OpenBadges Extension from versions 1.39.0 to 1.39.10, as well as versions 1.41.0 to 1.41.2 and 1.42.0 to 1.42.1.
CVE-2025-23080 allows attackers to execute arbitrary JavaScript in the context of the user's browser, leading to potential data theft or session hijacking.
If immediate upgrading is not possible for CVE-2025-23080, consider disabling the affected extension or implementing input validation mechanisms to mitigate XSS risks.