CyberRota Analysis
AI-GeneratedThe MassMessage extension in MediaWiki versions prior to 1.40.2 is vulnerable to cross-site scripting (XSS) via the Special:MassMessage?uselang=x-xss URL, which can be exploited through the i18n key massmessage-form-page-help. This vulnerability could allow an attacker to execute arbitrary scripts in the context of a user's session, potentially compromising user data and session integrity. Organizations using affected versions of MediaWiki should prioritize patching this vulnerability to mitigate the risk of XSS attacks.
Original NVD Description
An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.