BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.XSSMediaWiki / XSS
30 Sept 2026 · 3 min
MediaWiki / XSS · 30 Sept 2026

CVE-2026-103445: Stored XSS in PageForms auto-edit links

PageForms placed the #autoedit redirect value into a link without rejecting executable URL schemes.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

PageForms’ #autoedit parser function used its redirect value directly in the href of a generated link. An editor with ordinary page-edit permission could add a javascript: URL to a page.

Technical details

The page stored the crafted link, so the issue was persistent. A visitor who viewed the page and clicked the auto-edit link ran the URL in the wiki’s origin. The PoC uses a harmless marker that adds a data attribute to the local page body.

Reproduction

On a local wiki with PageForms enabled, save the PoC wikitext on a disposable editable page and click the generated Trigger link. The marker attribute appears on the page body.

Impact

An editor could place a same-origin script link on a page. A visitor had to click it for the script to run, after which it could act with that visitor’s wiki permissions.

References

1158 UTF-8 BYTES .WEB.XSS · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.