A stored cross-site scripting vulnerability affecting starcitizenwiki/embedvideo versions <= 4.0.0, with a CVSS score of 7.5, exists in the Mediawiki EmbedVideo Extension when $wgEmbedVideoRequireConsent is disabled, allowing an attacker to inject arbitrary JavaScript into HTML event handler attributes via malformed src URLs. This flaw can be exploited by any user able to edit a page without requiring interaction and executes in the wiki origin for every visitor to the page, posing a significant business impact as it allows unauthorized access to sensitive information and potentially enables malicious activities such as phishing or data theft.
We recommend you to update Mediawiki EmbedVideo Extension to version 4.1.0.[/subscribe_to_unlock_form]
A stored cross-site scripting vulnerability affecting starcitizenwiki/embedvideo versions <= 4.0.0, with a CVSS score of 7.5, exists in the Mediawiki EmbedVideo Extension when $wgEmbedVideoRequireConsent is disabled, allowing an attacker to inject arbitrary JavaScript into HTML event handler attributes via malformed src URLs. This flaw can be exploited by any user able to edit a page without requiring interaction and executes in the wiki origin for every visitor to the page, posing a significant business impact as it allows unauthorized access to sensitive information and potentially enables malicious activities such as phishing or data theft.
We recommend you to update Mediawiki EmbedVideo Extension to version 4.1.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]