← Back

CVE-2023-22911

nvd nist
Published: Jan 10, 2023Modified: Apr 7, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.

Affected (6)

1 product
Mediawiki
1 product
Fedora
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Before 1.35.9
From 1.36.0 to 1.38.5
Version 1.39.0
Version 1.39.0 rc0
Version 1.39.0 rc1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 37

Timeline

No history available yet.