Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-61642

Опубликовано: 02 фев. 2026
Источник: redhat
CVSS3: 4.6

Описание

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

A flaw was found in MediaWiki. This improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS), allows a remote attacker to inject malicious scripts into web pages viewed by other users. This can lead to information disclosure or other client-side attacks.

Отчет

This vulnerability involves a Stored Cross-site Scripting (XSS) flaw in MediaWiki, allowing an attacker to inject malicious scripts into system messages. When other users view these messages, the scripts could execute in their browsers. This issue affects MediaWiki versions prior to 1.39.14, 1.43.4, and 1.44.1. Red Hat products are not directly affected as MediaWiki is not a default component of Red Hat Enterprise Linux.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2436104MediaWiki: MediaWiki: Cross-site Scripting (XSS) vulnerability via improper input neutralization

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
2 месяца назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

CVSS3: 6.1
nvd
2 месяца назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

CVSS3: 6.1
debian
2 месяца назад

Improper Neutralization of Input During Web Page Generation (XSS or 'C ...

CVSS3: 6.1
github
2 месяца назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

4.6 Medium

CVSS3