Impact
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to version 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON returned through includes/EmbedService/AbstractEmbedService.php into the data‑mw‑iframeconfig attribute without safely escaping single quotes. Attacker‑controlled archiveorg identifiers and wistia or sharepoint URLs accepted by the affected service validators can cause getUrl() output to terminate the attribute and inject event‑handler attributes into the generated figure element. This vulnerability allows a user with editing rights to embed a specially crafted video URL in a MediaWiki page. A user able to edit a wiki page can store JavaScript that executes in the wiki origin when visitors render the page. The injected JavaScript is executed in the context of the wiki’s origin whenever any user views the page, permitting defacement, unauthorized data access, and potential session hijacking. This issue is fixed in version 4.1.0. The flaw represents a classic stored XSS flaw and does not provide any form of server‑side control or arbitrary code execution.
Affected Systems
The issue affects installations of the StarCitizenWiki MediaWiki extension EmbedVideo prior to version 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled. The vulnerability is triggered when the page author supplies a malicious video URL that bypasses the service validators. If an organization uses older versions of this extension, any page that has been edited to include the malformed video link is at risk.
Risk and Exploitability
With a CVSS score of 7.5 and an EPSS score below 1 %, the vulnerability is considered moderate‑high severity but low probability of widespread exploitation. It is not listed in CISA’s KEV catalog. An attacker must first have the ability to edit a wiki page, then craft a video URL containing a malicious payload. Once stored, the payload runs in the browser of any user who views the page, thereby affecting all visitors of that page. Based on the description, the likely attack vector is client‑side social engineering combined with content modification permissions; exploitation requires no network connectivity to the attacker’s machine beyond the page load.
OpenCVE Enrichment
Github GHSA