CVE-2025-7057: Stored XSS in Quiz
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Quiz Extension allows Stored XSS.This issue affects Mediawiki - Quiz Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7057?
CVE-2025-7057 is rated as a medium severity vulnerability that allows for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-7057?
To fix CVE-2025-7057, you should upgrade the Mediawiki - Quiz Extension to version 1.39.13, 1.42.7, or later.
Who is affected by CVE-2025-7057?
CVE-2025-7057 affects users of the Mediawiki - Quiz Extension versions prior to 1.39.13, 1.42.7, and 1.43.2.
What does CVE-2025-7057 exploit?
CVE-2025-7057 exploits improper neutralization of input during web page generation, leading to cross-site scripting vulnerabilities.
Can CVE-2025-7057 lead to data breaches?
Yes, CVE-2025-7057 can potentially lead to data breaches by allowing attackers to execute malicious scripts in the context of user sessions.