TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| starcitizentools/tabber-neue(Packagist) | 1.9.1 | 2.7.2 | N/A |
CVSS Metrics