Threat Advisory

Mediawiki EmbedVideo Extension Stored XSS via Malformed Src URL

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A stored cross-site scripting vulnerability affecting starcitizenwiki/embedvideo versions <= 4.0.0, with a CVSS score of 7.5, exists in the Mediawiki EmbedVideo Extension when $wgEmbedVideoRequireConsent is disabled, allowing an attacker to inject arbitrary JavaScript into HTML event handler attributes via malformed src URLs. This flaw can be exploited by any user able to edit a page without requiring interaction and executes in the wiki origin for every visitor to the page, posing a significant business impact as it allows unauthorized access to sensitive information and potentially enables malicious activities such as phishing or data theft.

RECOMMENDATION:

We recommend you to update Mediawiki EmbedVideo Extension to version 4.1.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A stored cross-site scripting vulnerability affecting starcitizenwiki/embedvideo versions <= 4.0.0, with a CVSS score of 7.5, exists in the Mediawiki EmbedVideo Extension when $wgEmbedVideoRequireConsent is disabled, allowing an attacker to inject arbitrary JavaScript into HTML event handler attributes via malformed src URLs. This flaw can be exploited by any user able to edit a page without requiring interaction and executes in the wiki origin for every visitor to the page, posing a significant business impact as it allows unauthorized access to sensitive information and potentially enables malicious activities such as phishing or data theft.

RECOMMENDATION:

We recommend you to update Mediawiki EmbedVideo Extension to version 4.1.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu