Impact
The vulnerability is a cross‑site scripting issue caused by improper neutralization of user‑controlled input in MediaWiki’s core log‑formatting code. Input that is incorporated into log entries can be rendered without escaping, allowing malicious code to be stored in the logs and executed when the log pages are viewed.
Affected Systems
MediaWiki installations from the earliest releases up to but not including version 1.46.0 are vulnerable, with documented affected releases being 1.45.4, 1.44.6, and 1.43.9. The problem resides in core files such as includes/Language.php, includes/Logging/BlockLogFormatter.php, LogFormatter.php, PatrolLogFormatter.php, RenameuserLogFormatter.php, TagLogFormatter.php, and includes/Specials/SpecialVersion.php.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low likelihood of exploitation, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector involves a web page that displays logs; by inserting unescaped data into a log entry, an attacker can cause arbitrary JavaScript to run when the log page is viewed.
OpenCVE Enrichment
Debian DSA