Impact
The vulnerability stems from improper neutralization of input during web page generation in the Wikimedia Foundation SyntaxHighlight_GeSHi library. A maliciously crafted value for the 'linelinks' attribute is stored in page source and later output without escaping, providing a persistent XSS vector. When a user views the affected page, the injected script runs in the user's browser with the same privileges as the page, potentially exposing session data or performing further malicious actions.
Affected Systems
All versions of Wikimedia Foundation SyntaxHighlight_GeSHi older than 1.46.0, including 1.45.4, 1.44.6, 1.43.9 and any earlier releases, are affected.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the moderate severity range. The EPSS score is below 1%, suggesting exploitation is currently unlikely, and the issue is not listed in the CISA KEV catalog. Attackers must embed malicious code into the 'linelinks' attribute during content creation; the stored value is then interpreted for each viewer, making the vulnerability potentially widespread if the attribute can be controlled.
OpenCVE Enrichment
Debian DSA