CVE-2023-45360

CVSS v3.1 5.4 (Medium)
54% Progress
EPSS 0.04 % (15th)
0.04% Progress
Affected Products 1
Advisories 2
NVD Status Modified

An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
NVD Status
Modified
CNA
MITRE
Published Date
2023-11-03 05:15:30
(10 months ago)
Updated Date
2024-07-03 01:41:52
(2 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mediawiki prior 1.35.12 version cpe:2.3:a:mediawiki:mediawiki < 1.35.12
  Mediawiki from 1.39.0 version and prior 1.39.5 version cpe:2.3:a:mediawiki:mediawiki >= 1.39.0 < 1.39.5
  Mediawiki 1.40.0 cpe:2.3:a:mediawiki:mediawiki:1.40.0:-
  Mediawiki 1.40.0 Rc0 cpe:2.3:a:mediawiki:mediawiki:1.40.0:rc0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...