Impact
The vulnerability is an Improper Neutralization of Input during Web Page Generation (CWE‑79) located in the blockConnectedTempAccountsField component of the Wikimedia Foundation CheckUser extension. An attacker can insert JavaScript into a system message that is then stored and rendered to anyone who views that message, enabling arbitrary client‑side code execution.
Affected Systems
1.46.0, including all 1.46.0‑rc.0 release candidates up to, but not including, 1.46.0, are affected. Administrators using any pre‑1.46.0 release should review the use of the blockConnectedTempAccountsField feature and determine whether the flaw could be activated in their environment.
Risk and Exploitability
The flaw is triggered by users who have permission to block temporary accounts and supply a crafted message. Based on the description, it is inferred that an attacker must have privileged access to undertake the block operation to inject malicious payloads into stored messages. The EPSS score is below 1 % and the issue is not listed in CISA’s KEV catalog, indicating no publicly known exploits and a low probability of exploitation. The attack does not provide server‑side code execution and is limited to privileged users.
OpenCVE Enrichment