Bug 2436106 (CVE-2025-61640)
| Summary: | CVE-2025-61640 MediaWiki: MediaWiki: Arbitrary code execution via Cross-site Scripting (XSS) | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in MediaWiki. A remote attacker can exploit this Cross-site Scripting (XSS) vulnerability by injecting malicious scripts into web pages due to improper neutralization of input during web page generation. This could lead to arbitrary code execution in the context of the user's browser, potentially allowing for information disclosure or session hijacking.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2436193, 2436199 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-02-03 00:01:45 UTC
|