Wikimedia Foundation MediaWiki BlueSky Skin Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in the Wikimedia Foundation MediaWiki BlueSky skin, affecting versions prior to 1.39. This issue arises from improper escaping of system message content, which is inserted as raw HTML, allowing malicious scripts to be executed.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Reproduction
To reproduce this vulnerability, edit the MediaWiki:Sidebar page and add a script tag containing JavaScript, such as an alert command. After saving the changes, visit any page where the sidebar is displayed. The injected script will execute, demonstrating the cross-site scripting vulnerability.
Remediation
Users can update to MediaWiki BlueSky skin version 1.39 or later, where this vulnerability has been addressed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
