CVE-2023-36675

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:10

Type Values Removed Values Added
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/ -
References () https://phabricator.wikimedia.org/T332889 - Exploit, Issue Tracking () https://phabricator.wikimedia.org/T332889 - Exploit, Issue Tracking
References () https://www.debian.org/security/2023/dsa-5447 - Third Party Advisory () https://www.debian.org/security/2023/dsa-5447 - Third Party Advisory
References () https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 - Vendor Advisory () https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 - Vendor Advisory

07 Nov 2023, 04:16

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/', 'name': 'FEDORA-2023-7e9d6015f6', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/', 'name': 'FEDORA-2023-1fcaba0998', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/', 'name': 'FEDORA-2023-d8ae3c122e', 'tags': [], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/ -

15 Sep 2023, 21:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/ -

02 Sep 2023, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/ -

31 Jul 2023, 13:05

Type Values Removed Values Added
References (MISC) https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 - (MISC) https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 - Vendor Advisory
References (DEBIAN) https://www.debian.org/security/2023/dsa-5447 - (DEBIAN) https://www.debian.org/security/2023/dsa-5447 - Third Party Advisory

06 Jul 2023, 12:15

Type Values Removed Values Added
References
  • (DEBIAN) https://www.debian.org/security/2023/dsa-5447 -

05 Jul 2023, 07:15

Type Values Removed Values Added
Summary An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature. An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
References
  • (MISC) https://www.mediawiki.org/wiki/Release_notes/1.40#Other_changes_in_1.40 -

03 Jul 2023, 19:20

Type Values Removed Values Added
First Time Mediawiki
Mediawiki mediawiki
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
CPE cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
References (MISC) https://phabricator.wikimedia.org/T332889 - (MISC) https://phabricator.wikimedia.org/T332889 - Exploit, Issue Tracking

26 Jun 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-26 01:15

Updated : 2024-11-21 08:10


NVD link : CVE-2023-36675

Mitre link : CVE-2023-36675

CVE.ORG link : CVE-2023-36675


JSON object : View

Products Affected

mediawiki

  • mediawiki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')