Wikimedia MediaWiki GoogleDocs4MW Extension Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the GoogleDocs4MW extension for MediaWiki. This issue arises from improper sanitization of the style parameter, which can be exploited to inject malicious scripts. The vulnerability affects GoogleDocs4MW versions 1.42.X prior to 1.42.7 and 1.43.X prior to 1.43.2.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, insert a specific payload into the Special:ExpandTemplates feature. The payload should include a Google Spreadsheet tag with a style parameter that contains a background image URL. After submitting the form, the injected URL will be accessed, demonstrating the cross-site scripting vulnerability.

Remediation

Users can update to GoogleDocs4MW version 1.42.7 or 1.43.2 to address this vulnerability.

Added: Jul 3, 2025, 5:31 PM
Updated: Jul 3, 2025, 6:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.