Impact
The vulnerability is an improper neutralization of input during web page generation (CWE‑79) located in the blockConnectedTempAccountsField component of the Wikimedia Foundation CheckUser extension. A malicious user who can block temporary accounts can insert a crafted JavaScript payload into the system message field. When that message is later displayed to any user, the injected script executes in the victim’s browser, resulting in stored cross‑site scripting that can be used to steal session cookies, deface content, or perform other client‑side attacks.
Affected Systems
Wikimedia Foundation CheckUser, from version 1.46.0-rc.0 up to but excluding 1.46.0, is affected. All pre‑1.46.0 releases that include the blockConnectedTempAccountsField feature are vulnerable. Administrators running those versions should verify whether the blocking feature is enabled and assess the potential exposure in their environments.
Risk and Exploitability
The flaw is triggered by users who have permission to block temporary accounts and supply crafted message. Based on the EPSS score of less than 1 % and the absence from the CISA KEV catalog, no publicly known exploits exist and the probability of exploitation is low. The attack does not provide server‑side code execution and is limited to privileged users with block rights, thereby restricting the overall risk to administrators.
OpenCVE Enrichment