CVE-2022-28202
Description
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
Risk Information
Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.527
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| mediawiki security update(DSA-5246-1) mediawiki_1.35.8-1~deb11u1_all.deb | Linux |
| mediawiki security update(DSA-5246-1) mediawiki_1.35.13-1~deb11u1_all.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234