ZeroHour

CVE-2023-37251

CVSS 3.1
6.1 medium
EPSS
<1%p34
Published
()
Modified
Description

An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.

Vendors
mediawiki
Products
mediawiki
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.