Description
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0009 | TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2. |
Github GHSA |
GHSA-4x6x-8rm8-c37j | Extension:TabberNeue vulnerable to Cross-site Scripting |
References
History
Mon, 06 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Jan 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2. | |
| Title | Cross-site Scripting in TabberTransclude in Extension:TabberNeue | |
| Weaknesses | CWE-79 CWE-80 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-26T19:48:04.827Z
Reserved: 2024-12-29T03:00:24.713Z
Link: CVE-2025-21612
Updated: 2025-01-06T16:52:21.396Z
Status : Deferred
Published: 2025-01-06T16:15:31.633
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-21612
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA