GHSA-hg8h-557g-q8pp
Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
Quick fix
GHSA-hg8h-557g-q8pp — mediawiki/semantic-media-wiki: upgrade to the fixed version with the command below.
composer require mediawiki/semantic-media-wiki:^7.0.0Details
### Summary The SemanticMediaWiki extension inserts the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext.
### Details
In `ext.smw.js`, the `data-subtab` attribute of all elements with the `smw-subtab` class is parsed as JSON and appended to the `innerHTML` of the element: https://github.com/SemanticMediaWiki/SemanticMediaWiki/blob/62f1fa765b626e21d88999b97a3e8029db9fd385/res/smw/ext.smw.js#L37-L42 However, most data attributes (except for reserved ones) like `data-subtab` can be used in wikitext. Therefore, it is possible to insert arbitrary HTML and JS through wikitext. The decoded (`"` will turn to `"`, but it will be decoded when it is retrieved through `.dataset`) value of the `data-subtab` attribute in the payload is `"<img src='' onerror=alert(1)>"`. This is valid JSON and returns a string with `<img src='' onerror=alert(1)>` when being decoded.
### PoC
1. Create a page with the following contents: ```html {{#tag:div| |class=smw-subtab |data-subtab=""<img src='' onerror=alert(1)>"" }} ``` 2. Visit the page
<img width="991" height="465" alt="image" src="https://github.com/user-attachments/assets/5d28d852-72d6-41dc-a59a-faac1610015f" /> <img width="497" height="69" alt="image" src="https://github.com/user-attachments/assets/02309390-0b40-46d9-b690-de8cd25dba59" />
### Impact
Arbitrary HTML can be inserted into the DOM by any user with the `edit` right, allowing for JavaScript to be executed.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.1.0Fixed in: 7.0.0composer require mediawiki/semantic-media-wiki:^7.0.0