Impact
The vulnerability allows an attacker to insert arbitrary script into table headers rendered by Semantic MediaWiki when the headers parameter is set to plain. By supplying malicious content in the user‑controlled mainlabel field, the application emits this content directly into a <th> element, leading to client‑side execution for anyone viewing the page. The flaw is a classic reflected XSS type weakness, identified as CWE‑79, which can undermine confidentiality and integrity by executing malicious JavaScript in the victim’s browser.
Affected Systems
Semantic MediaWiki, the open‑source MediaWiki extension, is affected in all releases prior to 7.2.0. Any installation that uses the headers=plain rendering mode and accepts user‑supplied mainlabel data is vulnerable. The fix is available in version 7.2.0 and later.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate risk, and the EPSS score is not available, making the exploitation likelihood difficult to quantify. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker constructing a special:ask query that includes a malicious mainlabel value and setting headers=plain; when the page renders, the attacker’s script executes in the context of any user who views the table.
OpenCVE Enrichment
Github GHSA