Description

An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because the line param can have markup.

INFO

Published Date :

2024-10-09T00:00:00.000Z

Last Modified :

2024-10-09T21:40:04.569Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2023-45359 vulnerability.

Vendors Products
Mediawiki
  • Vector Skin
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2023-45359.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact