Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-103585 — Sanitized report and loopback-only PoC script demonstrating stored XSS via javascript: license URLs in MediaSearch QuickView (CVE-2026-103585). | Kitploit
Tools/GitHubGitHub/bombobombone/cve-2026-103585
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPapers & Research
GitHubbombobombone/cve-2026-103585

CVE-2026-103585

Sanitized report and loopback-only PoC script demonstrating stored XSS via javascript: license URLs in MediaSearch QuickView (CVE-2026-103585).

View Repository
2 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-103585: Stored XSS in MediaSearch QuickView

Reporter: Marco Paciaroni (BomboBombone).

MediaSearch QuickView used CommonsMetadata's LicenseUrl.value directly as a link destination. CommonsMetadata copied the licensetpl_link value from an editable file description without restricting its URL scheme. An editor could store a javascript: URL; a visitor who opened that file in MediaSearch and followed the displayed license link could run script in the wiki origin.

The paired CVE-2026-103584 covers the CommonsMetadata source path.

Local reproduction

Use a disposable file description on a local test wiki with a harmless marker:

<span class="licensetpl"><span class="licensetpl_link">javascript:alert("CVE_LICENSE_URL_XSS")</span><span class="licensetpl_short">Test license</span><span class="licensetpl_long">Local test</span></span>

Then query the local API:

python poc.py --api http://127.0.0.1:8080/w/api.php --title File:LicenseUrlProbe.png

The script checks whether the API returns the executable scheme in LicenseUrl.value. To observe the browser behavior, open the file in the local MediaSearch QuickView and follow its license link. The script only permits loopback API URLs.

References

  • CVE record
  • Paired CommonsMetadata CVE-2026-103584
  • Phabricator report
  • MediaSearch fix on Gerrit
  • Blog write-up
Download Tool