An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
References
Link | Resource |
---|---|
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A/ | |
https://phabricator.wikimedia.org/T149488 | Exploit Issue Tracking Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-01-10T00:00:00
Updated: 2023-01-27T00:00:00
Reserved: 2023-01-10T00:00:00
Link: CVE-2023-22911
JSON object: View
NVD Information
Status : Modified
Published: 2023-01-10T08:15:10.433
Modified: 2023-11-07T04:07:31.473
Link: CVE-2023-22911
JSON object: View
Redhat Information
No data.
CWE