THREAT OPS › Threat News › [GHSA] GHSA-hg8h-557g-q8pp (high) — Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
[GHSA] GHSA-hg8h-557g-q8pp (high) — Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
GHSA-hg8h-557g-q8pp Severity: high CVE: CVE-2025-61682
Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
### Summary The SemanticMediaWiki extension inserts the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext.
### Details
In `ext.smw.js`, the `data-subtab` attribute of all elements
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- 62f1fa765b626e21d88999b97a3e8029db9fd385sha1
- CVE-2025-61682cve
Original source: https://github.com/advisories/GHSA-hg8h-557g-q8pp