CVE-2023-36675

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*

History

07 Nov 2023, 04:16

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/ -

31 Jul 2023, 13:05

Type Values Removed Values Added
References (DEBIAN) https://www.debian.org/security/2023/dsa-5447 - (DEBIAN) https://www.debian.org/security/2023/dsa-5447 - Third Party Advisory
References (MISC) https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 - (MISC) https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 - Vendor Advisory

06 Jul 2023, 12:15

Type Values Removed Values Added
References
  • (DEBIAN) https://www.debian.org/security/2023/dsa-5447 -

05 Jul 2023, 07:15

Type Values Removed Values Added
References
  • (MISC) https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 -
Summary An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature. An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.

03 Jul 2023, 19:20

Type Values Removed Values Added
First Time Mediawiki
Mediawiki mediawiki
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
References (MISC) https://phabricator.wikimedia.org/T332889 - (MISC) https://phabricator.wikimedia.org/T332889 - Exploit, Issue Tracking
CPE cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*

26 Jun 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-26 01:15

Updated : 2023-11-07 04:16


NVD link : CVE-2023-36675

Mitre link : CVE-2023-36675


JSON object : View

Products Affected

mediawiki

  • mediawiki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')