Executive brief
The Maps extension for MediaWiki, which allows users to embed interactive maps into wiki pages, is vulnerable to a security flaw that allows attackers to inject malicious scripts. By adding specially crafted text to a map's overlay settings, an attacker can execute code in the browsers of other users who view the map. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the ProfessionalWiki Maps extension for MediaWiki (mediawiki/maps). The vulnerability is located in the `display_map` parser function when the Leaflet service is utilized. The extension fails to properly escape overlay names provided in the `overlays` parameter before passing them to the Leaflet library, which subsequently renders them as raw HTML. An attacker with page editing permissions can exploit this by embedding malicious HTML/JavaScript in the wikitext. The issue is addressed in version 12.1.3.
Affected products
- ProfessionalWiki Maps < 12.1.3
Timeline
- 2026-05-28: disclosed
- 2026-07-02: advisory
- 2026-07-02: patched: Fixed in version 12.1.3