MediaWiki Hovercards extension Cross-site scripting Vulnerability - Jan15

Summary
This host is installed with Hovercards extension for MediaWiki and is prone to cross-site scripting vulnerability.
Impact
Successful exploitation will allow remote attacker to execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Impact Level: Application
Solution
Upgrade to Hovercards extension version 1.24 or later. For updates refer to http://www.mediawiki.org/wiki/Special:ExtensionDistributor/Popups
Insight
The flaw exist as input passed via text parameter to the 'Extension:Popups'. script is not validated before returning it to users.
Affected
Hovercards extension version before 1.24 for Mediawiki
Detection
Send a crafted HTTP POST request and check whether it is able to read cookie or not.
References