Impact
Improper neutralization of user input during web page generation allows an attacker to inject malicious JavaScript into the pretty‑printed API output when combined with a central authentication token. The flaw is a classic XSS vulnerability that can be triggered by a crafted API request that causes user data to be included in the output without proper encoding, enabling arbitrary code execution in the victim’s browser.
Affected Systems
MediaWiki and CentralAuth components of the Wikimedia Foundation are vulnerable in all releases before 1.46.0, 1.45.4, 1.44.6, and 1.43.9 for both products.
Risk and Exploitability
The EPSS score is < 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of exploitation. The CVSS score of 5.4 indicates moderate risk for cross‑site scripting. Attackers would need to craft a specific API request and, potentially, obtain a central authentication token to trigger the flaw.
OpenCVE Enrichment
Debian DSA