Medium severity6.1NVD Advisory· Published Jun 26, 2023· Updated Jun 17, 2026
CVE-2023-36675
CVE-2023-36675
Description
An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <1.35.11, 1.36.x through 1.38.x <1.38.7, 1.39.x <1.39.4
Patches
Vulnerability mechanics
References
6- phabricator.wikimedia.org/T332889nvdExploitIssue Tracking
- www.debian.org/security/2023/dsa-5447nvdThird Party Advisory
- www.mediawiki.org/wiki/Release_notes/1.40nvdVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/nvd
News mentions
0No linked articles in our index yet.