Wikimedia MediaWiki GoogleDocs4MW Extension Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the GoogleDocs4MW extension for MediaWiki. This issue arises from improper sanitization of the style parameter, which can be exploited to inject malicious scripts. The vulnerability affects GoogleDocs4MW versions 1.42.X prior to 1.42.7 and 1.43.X prior to 1.43.2.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, insert a specific payload into the Special:ExpandTemplates feature. The payload should include a Google Spreadsheet tag with a style parameter that contains a background image URL. After submitting the form, the injected URL will be accessed, demonstrating the cross-site scripting vulnerability.
Remediation
Users can update to GoogleDocs4MW version 1.42.7 or 1.43.2 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
