Impact
This vulnerability arises from an improper neutralization of input in the Wikibase extension, allowing attackers to embed malicious JavaScript into a system message that is not escaped when rendered. The stored payload executes in the browsers of any user who views the message, enabling session hijacking, defacement, or malware delivery. The weakness is identified as CWE-79.
Affected Systems
Affected are releases of the Wikimedia Foundation MediaWiki Wikibase Extension recorded as before 1.46.1, 1.45.5, and 1.43.10. Any site running those versions is susceptible, regardless of the Wikimedia project.
Risk and Exploitability
No official CVSS score is published and EPSS is unavailable, but the exploitability is high because the payload persists in the database. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploitation yet. Attackers can leverage available editing rights or credentials to inject the malicious system message, after which any visitor will execute the script automatically.
OpenCVE Enrichment