Impact
Improper neutralization of user input during page generation in the Cargo extension enables a stored cross‑site scripting vulnerability. An attacker could embed malicious script content that executes in the browsers of any user who later views a page that includes the manipulated input. This can lead to data theft, session hijacking, or defacement. The weakness is classified as CWE‑79.
Affected Systems
All installations of Mediawiki employing the Cargo extension with version 3.9.4 or earlier are effected. The vulnerability applies to Wikimedia Foundation builds that rely on the default hierarchy filter functionality provided by the Cargo extension.
Risk and Exploitability
The vulnerability receives a CVSS score of 6.9, indicating moderate severity. EPSS data is unavailable, and the flaw is not currently listed in the CISA KEV catalog. The likely attack vector involves a user submitting malicious content through the hierarchy filter, which is later rendered on a page without proper sanitization. Attackers would exploit this by prompting unsuspecting users to view the affected page, at which point the injected script runs. Given the stored nature of the flaw, any privileged or public user visiting the page can be impacted, but administrative privilege may be required to inject the payload during configuration.
OpenCVE Enrichment