Impact
The CommonsMetadata extension for MediaWiki fails to neutralize script‑related HTML tags in the license URL field, allowing attacker‑controlled JavaScript to be delivered to a victim’s browser. This flaw is a basic cross‑site scripting (CWE‑80) weakness; the injected code runs with the privileges of the page viewer but does not provide direct access to the server or its data.
Affected Systems
MediaWiki CommonsMetadata extension versions 1.46, 1.45, and 1.43 from The Wikimedia Foundation are impacted. No other MediaWiki extensions or related software vendors are listed.
Risk and Exploitability
The CVSS score of 1.1 indicates very low severity, and no EPSS score is available, so the probability of exploitation is unknown. The flaw is not present in CISA’s KEV catalog. The likely attack vector requires a victim to view a page that includes an attacker‑controlled license URL; no elevated privileges or authentication are required. Although the overall risk is modest, this vulnerability remains a client‑side scripting risk for any user who can view affected media pages.
OpenCVE Enrichment