Impact
The MediaWiki Collection (Book) extension contains a basic cross‑site scripting flaw caused by improper neutralization of script‑related HTML tags. Attackers can send malicious input through API endpoints that create session‑seeded javascript URLs, leading to the injection of executable scripts into pages viewed by other users. This could allow attackers to execute arbitrary JavaScript in the victim’s browser, potentially compromising session cookies, hijacking accounts, or performing phishing attacks. The flaw is classified as CWE‑80.
Affected Systems
Affected by versions 1.46, 1.45, and 1.43 of the MediaWiki Collection (Book) extension from The Wikimedia Foundation. Any installation deploying those versions is susceptible until updated.
Risk and Exploitability
The CVSS score is 1.1, indicating a very low severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires the attacker to craft a malicious API request; no publicly documented exploits exist. Nevertheless, the low score should not discourage remedial action, because any XSS could be used for framing or credential theft depending on context.
OpenCVE Enrichment