CVE-2025-43861 – ManageWiki Stored and Reflected XSS Vulnerability

The following table lists the changes that have been made to the
CVE-2025-43861 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 24, 2025

    Action Type Old Value New Value
    Added Description ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review dialog. A logged-in attacker must change a form field to include a malicious payload. If that same user then opens the “Review Changes” dialog, the payload will be rendered and executed in the context of their own session. This issue has been patched in commit 2f177dc.
    Added CVSS V3.1 AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
    Added CWE CWE-79
    Added Reference https://github.com/miraheze/ManageWiki/commit/2f177dc83b28b727613215b835d4036cb179e4ab
    Added Reference https://github.com/miraheze/ManageWiki/security/advisories/GHSA-859x-46h8-vcrv
Share the Post:

Related Posts