Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gr6v-3pmp-996p | Cargo Mediawiki Extension vulnerable to Cross-site Scripting |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 20 Oct 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediawiki
Mediawiki mediawiki |
|
| Vendors & Products |
Mediawiki
Mediawiki mediawiki |
Sat, 18 Oct 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: master. | |
| Title | Stored XSS through wikitext in Cargo | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: wikimedia-foundation
Published:
Updated: 2025-10-20T16:30:37.642Z
Reserved: 2025-10-18T04:03:51.880Z
Link: CVE-2025-62671
Updated: 2025-10-20T16:30:27.122Z
Status : Awaiting Analysis
Published: 2025-10-18T05:15:34.830
Modified: 2025-10-21T19:31:25.450
Link: CVE-2025-62671
No data.
OpenCVE Enrichment
Updated: 2025-10-20T13:21:45Z
Github GHSA