An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2023-01-10T00:00:00.000Z
Updated: 2025-04-07T18:36:08.229Z
Reserved: 2023-01-10T00:00:00.000Z
Link: CVE-2023-22911

Updated: 2024-08-02T10:20:31.462Z

Status : Modified
Published: 2023-01-10T08:15:10.433
Modified: 2025-04-07T19:15:51.443
Link: CVE-2023-22911
