Impact
The vulnerability is an improper neutralization of script‑related HTML tags, enabling stored Cross‑Site Scripting in system messages on the MediaWiki WikiForum extension. Because the payload is persisted, an attacker who can write messages can embed arbitrary script that will be executed in the browsers of all users who view those messages. The injected code could read cookies, session tokens, or perform actions on behalf of the victim, leading to loss of confidentiality, integrity, and possibly account compromise. The weakness is identified as CWE‑80.
Affected Systems
The flaw affects the MediaWiki WikiForum extension, specifically the master branch where the issue was discovered. Users running this extension without the patch are vulnerable. The product is maintained by the Wikimedia Foundation. No explicit version numbers are supplied, so the risk applies to all instances that have not yet incorporated the latest build where the fix is present.
Risk and Exploitability
The CVSS score is 1.1, indicating a very low severity under standard scoring. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploitation is unlikely at present. However, because the attack vector is likely remote – any authenticated or possibly unauthenticated user could create messages – the risk may increase if the platform is exposed to a broader audience. Administrators should nevertheless address the issue promptly to eliminate the potential for XSS abuse.
OpenCVE Enrichment