Mediawiki OpenBadges Extension是美国维基媒体(Wikimedia)基金会的一个扩展。 Mediawiki OpenBadges Extension存在跨站脚本漏洞。攻击者利用该漏洞可以执行跨站脚本攻击。以下版本受到影响:1.39.X版本至1.39.11之前版本、1.41.X版本至1.41.3之前版本和1.42.X版本至1.42.2之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Wikimedia Foundation | Mediawiki - OpenBadges Extension | 1.39.x ~ 1.39.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-23074 | Special:EditProfile exposes the contents of profile fields marked "hidden"/friends or "fri | |
| CVE-2025-23073 | API list=globalblocks can reveal IP of autoblock if username and IP are included in the bg | |
| CVE-2025-23081 | Various security vulnerabilities in Extension:DataTransfer | |
| CVE-2025-23072 | XSS in Special:RefreshSpecial |
No comments yet