Impact
Improper neutralization of script‑related HTML tags in the Multimedia Foundation MediaWiki Page_Forms extension creates a stored XSS vulnerability. The flaw allows an attacker to embed arbitrary JavaScript via PageForms autoedit redirect links, causing the code to execute in the browsers of any user who later views the affected page. A malicious script could steal session cookies, deface content, or hijack user accounts; the impact therefore touches confidentiality, integrity, and potentially availability of the site.
Affected Systems
The vulnerability is present in the MediaWiki Page_Forms extension versions 1.46, 1.45, and 1.43. These are maintained by the Wikimedia Foundation.
Risk and Exploitability
The CVSS score of 1.2 indicates low overall severity, and the EPSS score is not available, suggesting that exploitation is not widely observed. The flaw is not listed in the CISA KEV catalog. Exploitation typically requires an authenticated user with editing privileges to create or modify a PageForm that contains a redirect link, so the attack surface is limited to users with such permissions. Nonetheless, because the XSS is stored, any subsequent visitor to the page will be affected until the content is cleaned or the extension is upgraded.
OpenCVE Enrichment