Wikimedia Foundation MediaWiki MintyDocs Extension Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Wikimedia Foundation MediaWiki MintyDocs Extension, specifically in versions 1.39.X, 1.42.X, and 1.43.X prior to 1.43.2. This vulnerability arises from improper input sanitization during web page generation, allowing users to inject malicious JavaScript that is saved and executed later.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the page.

Reproduction

The vulnerability can be reproduced by using the MintyDocs topic parser function to insert JavaScript into a Wikitext field that does not properly escape or sanitize the input. This injected script is then executed when the page is viewed, demonstrating the stored cross-site scripting flaw.

Remediation

Users can update to MintyDocs Extension versions 1.43.2 or later to address this vulnerability.

Added: Jul 2, 2025, 3:25 PM
Updated: Jul 2, 2025, 4:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.