Impact
The ReadingLists extension fails to neutralize script‑related HTML tags in imported metadata, allowing an attacker to embed a JavaScript URL that will execute in the victim’s browser when the metadata is viewed. The malicious code runs with the user’s privileges, potentially hijacking sessions or redirecting to malicious sites. This is a basic reflected XSS vulnerability, meaning the attacker simply needs to craft a URL containing the malicious metadata and get a user to open it. The description explicitly states the flaw is a Reflected XSS due to improper neutralization of script tags.
Affected Systems
The flaw is present in MediaWiki ReadingLists extension versions 1.46 and 1.45 as used by The Wikimedia Foundation. All installations using those extension versions remain vulnerable until the extension is upgraded to a fixed release.
Risk and Exploitability
The CVSS score of 1.1 indicates a low overall severity. No EPSS data is available, so the precise exploitation probability is unknown; however, based on the description, the vulnerability requires user interaction to trigger the reflected XSS, which suggests widespread automated exploitation is unlikely. The vulnerability is not listed in CISA’s KEV catalogue, further indicating limited exposure at present.
OpenCVE Enrichment