Impact
Improper neutralization of script tags in the MediaWiki MediaSearch extension allows attacker‑controlled JavaScript to be injected via the license URL field. This basic XSS flaw can lead to client‑side script execution, potentially hijacking user sessions or enabling further attacks on the site.
Affected Systems
MediaWiki MediaSearch extension versions 1.46, 1.45, and 1.43 are affected. The flaw resides in the license URL handling of these extensions.
Risk and Exploitability
The CVSS score is 1.2, indicating low severity, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a malicious license URL that an end user will load, making it a client‑side XSS exploit dependent on users viewing a compromised page. While low-scoring, compromised users could still be impacted.
OpenCVE Enrichment