CNNVD-202510-2589 Information
Oct 20, 2025
cve
CNNVD ID
CNNVD-202510-2589
Related CVE
- CNNVD Published: 2025-10-20
Description (Chinese)
MediaWiki - LastModified Extension是MediaWiki开源的一个展示Wiki条目最后修改日期的扩展。 MediaWiki - LastModified Extension 1.39之前版本存在安全漏洞,该漏洞源于输入中和不当,可能导致存储型跨站脚本攻击。
Description (English)
MediaWiki - LastModified Extension is an extension of MediaWiki ’ s open source to show the date of final modification of the Wiki entry. The previous version of MediaWiki - LastModified Extension 1.39 had a security loophole, which originated in inappropriate input and could lead to storage-type cross-station script attacks.
Hazard Level
Medium
Vulnerability Type
其他
Affected Vendor
维基媒体
Published
2025-10-20
Last Modified
2026-02-24
References
https://gerrit.wikimedia.org/r/q/Ia406630dbac5ef9a9aed3f402f0ba6e434a6bcf2 https://phabricator.wikimedia.org/T399583
Patch
https://phabricator.wikimedia.org/T399583
Share on: