CVE-2025-32074: XSSes in Extension:ConfirmAccount
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Confirm Account Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Confirm Account Extension: from 1.39 through 1.43.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32074?
The severity of CVE-2025-32074 is classified as high due to its potential for Cross-Site Scripting (XSS).
How do I fix CVE-2025-32074?
To fix CVE-2025-32074, you should update the Wikimedia Foundation Mediawiki - Confirm Account Extension to a version higher than 1.43.
What causes CVE-2025-32074?
CVE-2025-32074 is caused by improper encoding or escaping of output within the Mediawiki - Confirm Account Extension.
What versions are affected by CVE-2025-32074?
CVE-2025-32074 affects Mediawiki - Confirm Account Extension versions from 1.39 through 1.43.
What type of attack is associated with CVE-2025-32074?
CVE-2025-32074 is associated with Cross-Site Scripting (XSS) attacks.