CVE-2023-36675

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*

History

07 Nov 2023, 04:16

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/', 'name': 'FEDORA-2023-7e9d6015f6', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/', 'name': 'FEDORA-2023-d8ae3c122e', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/', 'name': 'FEDORA-2023-1fcaba0998', 'tags': [], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/ -

15 Sep 2023, 21:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/ -

02 Sep 2023, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/ -

31 Jul 2023, 13:05

Type Values Removed Values Added
References (DEBIAN) https://www.debian.org/security/2023/dsa-5447 - (DEBIAN) https://www.debian.org/security/2023/dsa-5447 - Third Party Advisory
References (MISC) https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 - (MISC) https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 - Vendor Advisory

06 Jul 2023, 12:15

Type Values Removed Values Added
References
  • (DEBIAN) https://www.debian.org/security/2023/dsa-5447 -

05 Jul 2023, 07:15

Type Values Removed Values Added
References
  • (MISC) https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 -
Summary An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature. An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.

03 Jul 2023, 19:20

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References (MISC) https://phabricator.wikimedia.org/T332889 - (MISC) https://phabricator.wikimedia.org/T332889 - Exploit, Issue Tracking
First Time Mediawiki mediawiki
Mediawiki
CPE cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*

26 Jun 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-26 01:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-36675

Mitre link : CVE-2023-36675

CVE.ORG link : CVE-2023-36675


JSON object : View

Products Affected

mediawiki

  • mediawiki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')