EmbedVideo 扩展是一个 MediaWiki 扩展,它添加了一个名为 的解析函数以及多种解析标签,用于嵌入来自各种视频分享服务的视频片段。 在 4.1.0 版本之前,当启用默认的 配置时, 文件会将通过 返回的 JSON 数据直接放入 属性中,而未对单引号进行安全转义。 攻击者可通过控制 的标识符,或提供被受影响的服务验证器所接受的 Wistia 或 SharePoint URL,使 函数的输出能够终止该 HTML 属性,并借此向生成的 元素中注入事件处理器属性(如 、 等)。 任何能够编辑维基页面的用户均
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| StarCitizenWiki | mediawiki-extensions-EmbedVideo | < 4.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55691 | 8.6 HIGH | EmbedVideo Extension : Stored XSS via unsanitized class passed to template |
| CVE-2026-55690 | 7.5 HIGH | EmbedVideo Extension: Stored XSS via unsanitized service name in exception text |
No comments yet