Impact
Semantic MediaWiki, an open‑source extension for MediaWiki, contains a reflected cross‑site scripting flaw in the Special:SearchByProperty page. The vulnerability arises when the "value" parameter is reflected back into rendered output and error messages without adequate output‑context encoding. An attacker can inject malicious JavaScript via a crafted URL, allowing arbitrary script execution in the victim’s browser. The weakness aligns with CWE‑79.
Affected Systems
The flaw affects any MediaWiki instance that installs Semantic MediaWiki versions earlier than 7.2.0. Systems that expose the "property" and "value" query parameters on the Special:SearchByProperty page are vulnerable. The vulnerable products include the Semantic MediaWiki extension for MediaWiki across all releases before 7.2.0.
Risk and Exploitability
The CVSS score of 6.1 rates the issue as medium severity. EPSS is unavailable and the vulnerability is not listed in CISA’s KEV catalog, so no evidence of active exploitation in the wild exists. Nevertheless, an attacker could entrap users with a malicious link, resulting in theft of credentials or defacement. The attack vector is primarily through crafted URLs that a victim follows, making the risk user‑centric and mitigable by applying the vendor’s patch or disabling the vulnerable functionality.
OpenCVE Enrichment
Github GHSA