6.1
CVSSv3

CVE-2023-36675

Published: 26/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in MediaWiki prior to 1.35.11, 1.36.x up to and including 1.38.x prior to 1.38.7, and 1.39.x prior to 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki

Vendor Advisories

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting, a bypass of vandalism protections or information disclosure For the oldstable distribution (bullseye), these problems have been fixed in version 1:13511-1~deb11u1 For the stable distribution (bookworm), the ...
DescriptionThe MITRE CVE dictionary describes this issue as: An issue was discovered in MediaWiki before 13511, 136x through 138x before 1387, 139x before 1394, and 140x before 1401 BlockLogFormatterphp in BlockLogFormatter allows XSS in the partial blocks feature ...