Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation (CWE‑79) flaw in MediaWiki that allows a malicious user to inject arbitrary JavaScript into the Special:ApiSandbox page. This stored cross‑site scripting can be abused when a deprecated module is selected, enabling session hijacking, defacement, or other client‑side attacks if an attacker can influence input that is subsequently rendered.
Affected Systems
MediaWiki versions from 1.46.0‑rc.0 through just before the final 1.46.0 release are vulnerable. Any installation derived from these releases uses the Special:ApiSandbox interface and the deprecated module, placing it at risk.
Risk and Exploitability
The CVSS score of 4.6 indicates low‑to‑moderate severity, and the EPSS score of less than 1 % suggests a very low probability of exploitation. The issue is not listed in CISA KEV. The likely attack vector is web‑based interaction with the Special:ApiSandbox page, where an attacker can provide malicious input that is stored and later rendered to users, producing client‑side code execution.
OpenCVE Enrichment