{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2018-25089","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2023-08-26T20:13:13.681Z","datePublished":"2023-08-28T12:31:04.889Z","dateUpdated":"2024-09-30T17:50:45.123Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2023-10-20T12:43:24.091Z"},"title":"glb Meetup Tag Extension Link Attribute reverse tabnabbing","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-1022","lang":"en","description":"CWE-1022 Use of Web Link to Untrusted Target with window.opener Access"}]}],"affected":[{"vendor":"glb","product":"Meetup Tag Extension","versions":[{"version":"0.1","status":"affected"}],"modules":["Link Attribute Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in glb Meetup Tag Extension 0.1 on MediaWiki. It has been rated as problematic. This issue affects some unknown processing of the component Link Attribute Handler. The manipulation leads to use of web link to untrusted target with window.opener access. Upgrading to version 0.2 is able to address this issue. The identifier of the patch is 850c726d6bbfe0bf270801fbb92a30babea4155c. It is recommended to upgrade the affected component. The identifier VDB-238157 was assigned to this vulnerability."},{"lang":"de","value":"Eine Schwachstelle wurde in glb Meetup Tag Extension 0.1 für MediaWiki ausgemacht. Sie wurde als problematisch eingestuft. Dies betrifft einen unbekannten Teil der Komponente Link Attribute Handler. Durch das Manipulieren mit unbekannten Daten kann eine use of web link to untrusted target with window.opener access-Schwachstelle ausgenutzt werden. Ein Aktualisieren auf die Version 0.2 vermag dieses Problem zu lösen. Der Patch wird als 850c726d6bbfe0bf270801fbb92a30babea4155c bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":2.7,"vectorString":"AV:A/AC:L/Au:S/C:N/I:P/A:N"}}],"timeline":[{"time":"2018-02-22T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2018-02-22T00:00:00.000Z","lang":"en","value":"Countermeasure disclosed"},{"time":"2023-08-26T00:00:00.000Z","lang":"en","value":"CVE reserved"},{"time":"2023-08-26T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2023-09-20T17:26:00.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"VulDB GitHub Commit Analyzer","type":"tool"}],"references":[{"url":"https://vuldb.com/?id.238157","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.238157","tags":["signature","permissions-required"]},{"url":"https://github.com/glb/mediawiki-tag-extension-meetup/commit/850c726d6bbfe0bf270801fbb92a30babea4155c","tags":["patch"]},{"url":"https://github.com/glb/mediawiki-tag-extension-meetup/releases/tag/v0.2","tags":["patch"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T12:33:47.884Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.238157","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.238157","tags":["signature","permissions-required","x_transferred"]},{"url":"https://github.com/glb/mediawiki-tag-extension-meetup/commit/850c726d6bbfe0bf270801fbb92a30babea4155c","tags":["patch","x_transferred"]},{"url":"https://github.com/glb/mediawiki-tag-extension-meetup/releases/tag/v0.2","tags":["patch","x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-30T17:49:57.600187Z","id":"CVE-2018-25089","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-30T17:50:45.123Z"}}]}}