CVE-2023-45360

An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers.
References
Link Resource
https://phabricator.wikimedia.org/T340221 Exploit Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.40.0:-:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.40.0:rc0:*:*:*:*:*:*

History

09 Nov 2023, 22:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79
References (MISC) https://phabricator.wikimedia.org/T340221 - (MISC) https://phabricator.wikimedia.org/T340221 - Exploit, Issue Tracking, Patch, Vendor Advisory
First Time Mediawiki
Mediawiki mediawiki
CPE cpe:2.3:a:mediawiki:mediawiki:1.40.0:rc0:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.40.0:-:*:*:*:*:*:*

03 Nov 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-03 05:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-45360

Mitre link : CVE-2023-45360

CVE.ORG link : CVE-2023-45360


JSON object : View

Products Affected

mediawiki

  • mediawiki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')