An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-01-10T00:00:00

Updated: 2024-08-02T10:20:31.462Z

Reserved: 2023-01-10T00:00:00

Link: CVE-2023-22911

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-01-10T08:15:10.433

Modified: 2023-11-07T04:07:31.473

Link: CVE-2023-22911

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-01-10T00:00:00Z

Links: CVE-2023-22911 - Bugzilla