CVE-2023-37255
29.06.2023, 16:15
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header.
Vendor | Product | Version |
---|---|---|
mediawiki | mediawiki | 𝑥 ≤ 1.39.3 |
𝑥
= Vulnerable software versions