XSS Vulnerability in MobileFrontend Extension for MediaWiki
CVE-2019-14807
6.1MEDIUM
What is CVE-2019-14807?
A Cross-Site Scripting (XSS) vulnerability exists in the MobileFrontend extension for MediaWiki, specifically affecting versions 1.31 through 1.33. This flaw allows attackers to inject malicious scripts via the edit summary field in MobileSpecialPageFeed.php, potentially compromising the security of users interacting with the application. It highlights the importance of sanitizing user inputs to prevent XSS attacks and ensures robust security measures are implemented.
