Impact
The vulnerability in the MediaWiki Wikibase extension allows an attacker to inject arbitrary script code into a web page due to improper neutralization of script‑related HTML tags. This basic cross‑site scripting flaw can result in the execution of malicious scripts in the context of the victim’s session, potentially leading to theft of credentials, session hijacking, or distribution of malware.
Affected Systems
Affected systems include the Wikimedia Foundation’s MediaWiki Wikibase extension across version 1.46, 1.45 and 1.43. These versions are currently vulnerable to XSS until a patch or upgrade is applied.
Risk and Exploitability
With a CVSS score of 0.3 the severity is low and no recent public exploits are known or listed in the KEV catalog. The EPSS score is not available. Exploitation would likely require the attacker to supply crafted content that is subsequently rendered in a page, suggesting the attack vector is through user‑generated input or article edits. Given the low score it is unlikely to be widely exploited, but the presence of XSS remains a concern for confidentiality and integrity.
OpenCVE Enrichment