CVE-2023-45361Mediawiki vulnerability

4 documents4 sources
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 59.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 9

Description

An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it is not a valid title, leading to incorrect web pages.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

debiandebian/mediawiki< mediawiki 1:1.39.5-1~deb12u1 (bookworm)
Debianmediawiki/mediawiki< 1:1.39.5-1~deb12u1+2

🔴Vulnerability Details

2
GHSA
GHSA-vcv5-qjfg-9jmc: An issue was discovered in VectorComponentUserLinks2024-10-09
OSV
CVE-2023-45361: An issue was discovered in VectorComponentUserLinks2024-10-09

📋Vendor Advisories

1
Debian
CVE-2023-45361: mediawiki - An issue was discovered in VectorComponentUserLinks.php in the Vector Skin compo...2023