Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Breadcrumbs2 extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.5, from 1.42.X before 1.42.4.
History

Fri, 10 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Breadcrumbs2 extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.5, from 1.42.X before 1.42.4.
Title XSS in BreadCrumbs2
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published: 2025-01-10T17:57:20.927Z

Updated: 2025-01-10T17:57:20.927Z

Reserved: 2025-01-10T17:00:37.685Z

Link: CVE-2025-23078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-01-10T18:15:26.877

Modified: 2025-01-10T18:15:26.877

Link: CVE-2025-23078

cve-icon Redhat

No data.