Impact
The vulnerability is an improper neutralization of input during web page generation (CWE-79) located in the blockConnectedTempAccountsField component of the Wikimedia Foundation CheckUser extension. The likely attack vector is a malicious user who can block temporary accounts inserting a crafted JavaScript payload into the system message field. When that message is later displayed to any user, the injected script executes in the victim’s browser, resulting in stored cross‑site scripting that can be used to steal session cookies, deface content, or perform other client‑side attacks.
Affected Systems
Wikimedia Foundation CheckUser, from version 1.46.0-rc.0 up to but excluding 1.46.0, is affected. All pre‑1.46.0 releases that include the blockConnectedTempAccountsField feature are vulnerable. Administrators running those versions should verify whether the blocking feature is enabled and assess the potential exposure in their environments.
Risk and Exploitability
Based on the description, it is inferred that the flaw is triggered by users who have permission to block temporary accounts and supply a crafted message, and the CVSS score of 4.8 indicates a moderate severity risk. Based on the EPSS score of less than 1 % and the absence from the CISA KEV catalog, no publicly known exploits exist and the probability of exploitation is low. The attack does not provide server‑side code execution and is limited to privileged users with block rights, thereby restricting the overall risk to administrators.
OpenCVE Enrichment