Impact
A Cross‑Site Scripting vulnerability exists in the MassMessage extension of MediaWiki for releases prior to 1.40.2. An attacker can trigger arbitrary JavaScript by crafting a URL such as Special:MassMessage?uselang=x‑xss, where the i18n key massmessage‑form‑page‑help is not properly sanitized. This flaw allows malicious code to run in the context of any user who views the affected page, potentially enabling credential theft, session hijacking, or defacement.
Affected Systems
All MediaWiki installations that employ the MassMessage extension before version 1.40.2 and allow the uselang parameter to be set via URLs are susceptible. Systems that use the extension in production environments and expose the Special:MassMessage interface without strict access controls are included.
Risk and Exploitability
The CVSS base score is 5.4, indicating a moderate impact. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is social engineering or a public link that directly targets the uselang parameter, with no authentication required. Exploitation requires only the ability to send or trick a user into visiting the crafted URL.
OpenCVE Enrichment