Impact
Improper neutralization of user‑supplied input during page generation allows an attacker to inject malicious JavaScript through the pretty‑printed API output when combined with a central authentication token. The flaw is an XSS vulnerability that can act on API requests that cause the output to include user data without proper encoding.
Affected Systems
MediaWiki and CentralAuth from the Wikimedia Foundation are affected.46.0, 1.45.4, 1.44.6, and 1.43.9, and the corresponding CentralAuth releases with the same version thresholds, are vulnerable.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve a crafted API request that triggers the pretty with the exposure of the affected API endpoints to unauthenticated or low‑privilege users.
OpenCVE Enrichment
Debian DSA