Impact
The vulnerability is a CWE‑79: Improper Neutralization of Input During Web Page Generation. An attacker can inject malicious script code into a system message used by the codex version of Special:Block. Once this script is stored, it is rendered and executed in the browsers of any MediaWiki user who views the affected page, potentially enabling malicious actions by the attacker.
Affected Systems
The affected vendor is Wikimedia Foundation MediaWiki. Any deployment that still contains the vulnerable Special:Block codex implementation located in resources/src/mediawiki.Special.Block/SpecialBlock.Vue is at risk; no specific version range is documented.
Risk and Exploitability
The EPSS score of < 1% indicates a very low, but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector requires an attacker who can insert or modify a system message that is displayed by Special:Block; the stored script is then executed for users who view the page.
OpenCVE Enrichment