Google Analytics Metrics Extension for MediaWiki JavaScript Escaping Vulnerability Allowing Cross-Site Scripting
Vulnerability
A cross-site scripting vulnerability has been identified in the GoogleAnalyticsMetrics extension for MediaWiki, affecting versions through 1.39.3. The issue arises because the googleanalyticstrackurl parser function fails to properly escape JavaScript in the onclick handler and does not block the use of javascript: URLs. This oversight allows for the injection of malicious JavaScript, which could be executed in the context of the user's browser.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user.
Remediation
Users can update to GoogleAnalyticsMetrics extension versions 1.39.4 or 1.40.1, where this vulnerability has been addressed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
