Impact
The EmbedVideo extension processes a user‑supplied class value without sanitization, inserting it directly into the figure element’s class attribute. This flaw permits a malicious user to inject a quote that terminates the class string and appends arbitrary HTML attributes or JavaScript. When a page containing the vulnerable tag is rendered, the injected script executes in the user’s browser, potentially enabling cookie theft or session hijacking.
Affected Systems
The vulnerability exists in the StarCitizenWiki mediawiki-extensions-EmbedVideo extension in all releases before version 4.1.0. Any MediaWiki site that has not updated past this release is affected and can accept stored malicious markup via its parser functions or tags.
Risk and Exploitability
The CVSS score of 8.6 classifies the flaw as high severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploit as of now. However, the user with edit rights can create or modify a page to include the vulnerable class value, resulting in persistent script injection for all anonymous and authenticated visitors alike. The impact is confined to client browsers, but it can compromise user sessions, credentials, and potentially other sensitive data exposed in the context of the wiki.
OpenCVE Enrichment
Github GHSA