Medium severity6.1NVD Advisory· Published Jun 29, 2023· Updated Jun 17, 2026
CVE-2023-37251
CVE-2023-37251
Description
An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <=1.39.3
- MediaWiki/GoogleAnalyticsMetricsdescription
Patches
Vulnerability mechanics
References
1- phabricator.wikimedia.org/T333980nvdVendor Advisory
News mentions
0No linked articles in our index yet.