Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22911


An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.


Published

2023-01-10T08:15:10.433

Last Modified

2025-04-07T19:15:51.443

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mediawiki mediawiki < 1.35.9 Yes
Application mediawiki mediawiki < 1.38.5 Yes
Application mediawiki mediawiki 1.39.0 Yes
Application mediawiki mediawiki 1.39.0 Yes
Application mediawiki mediawiki 1.39.0 Yes
Operating System fedoraproject fedora 37 Yes

References