CVE-2023-45359

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-45359
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-45359.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-45359
Related
Published
2024-10-09T06:15:13Z
Modified
2024-12-29T18:00:08.210017Z
Summary
[none]
Details

An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because the line param can have markup.

References

Affected packages

Debian:12 / mediawiki

Package

Name
mediawiki
Purl
pkg:deb/debian/mediawiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.39.5-1~deb12u1

Affected versions

1:1.*

1:1.39.2-1
1:1.39.4-1~deb12u1
1:1.39.4-1
1:1.39.4-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}