Wikimedia Foundation CheckUser
cpe:2.3:a:mediawiki:checkuser:*:*:*:*:mediawiki:*:*
- < 795bf333272206a0189050d975e94b70eb7dc507
A stored cross-site scripting vulnerability has been identified in the CheckUser extension of Wikimedia Foundation. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be executed. The vulnerability affects CheckUser versions prior to the commit 795bf333272206a0189050d975e94b70eb7dc507.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
The vulnerability can be reproduced by injecting a script into a message key that is then displayed by the CheckUser User Info Card feature. This can be done by overriding group messages with a payload that includes JavaScript, such as an image tag with an 'onerror' event.
A patch has been developed and applied to the affected version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.