Impact
An improper neutralization of user input during page rendering causes a reflected cross‑site scripting (XSS) vulnerability. The flaw resides in the language validation of the Special:SetLabel interface, allowing malicious script to be injected into rendered pages. If successfully exploited, a malicious actor might be able to manipulate the content seen by other users, potentially enabling session hijacking, defacement, or the delivery of arbitrary code in the victim’s browser; these consequences are inferred based on the nature of reflected XSS, not directly stated in the CVE description.
Affected Systems
The issue affects the Wikimedia Foundation MediaWiki Wikibase Extension. Vulnerable releases include all versions prior to 1.46.1, 1.45.5, and 1.43.10.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via crafted input to Special:SetLabel, which is a web interface; however, the description does not specify authentication requirements, so it is unclear whether elevation of privilege is needed. Consequently, the risk is moderate but potentially higher in environments where the Special:SetLabel function is exposed to untrusted users.
OpenCVE Enrichment