Cross-Site Scripting in the extensions, settings, permissions and namespaces subpages of Special:ManageWiki
Package
ManageWiki
(MediaWiki Extension)
Affected versions
All before 886cc6b94587f1c7387caa26ca9fe612e01836a0
Patched versions
Fully fixed in 6942e8b2c01dc33c2c41a471f91ef3f6ca726073
Impact
Special:ManageWiki does not escape interface messages on the
columns
andhelp
keys on the form descriptor.Exploiting this on-wiki requires the
(editinterface)
right.Patches
All of these must be applied in order to fully fix this vulnerability
Workarounds
None
References
https://issue-tracker.miraheze.org/T11812
For more information
If you have any questions or comments about this advisory: