Cross-Site Scripting in MobileFrontend Extension of MediaWiki
CVE-2019-15124
6.1MEDIUM
What is CVE-2019-15124?
The MobileFrontend extension for MediaWiki contains a Cross-Site Scripting vulnerability within the edit summary field of the watchlist feed. This issue allows attackers to inject malicious scripts that can be executed in the context of the user’s session, potentially leading to unauthorized access or data manipulation. It affects various versions, specifically REL1_31, REL1_32, and REL1_33, posing a risk to users interacting with the affected components.
