This was found during security review when requested for installation, so the extension is not installed on Miraheze yet
Corresponding Miraheze issue tracker task: https://issue-tracker.miraheze.org/T12979
System message: articlefeedbackv5-activity-pane-header
Cause: https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/extensions/ArticleFeedbackv5/+/aa0e2e6dfe9e1004d145f2a787b59885688464c5/modules/jquery.articleFeedbackv5/jquery.articleFeedbackv5.special.js#1709
Screenshot:
Example reproduction steps:
- Leave some feedback on a page
- Go to Special:ArticleFeedbackv5
- Mark feedback as inappropriate
- Request oversight on feedback
- Refresh page
- Find that comment again
- View activity
System messages: articlefeedbackv5-bucket?-title
Cause: https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/extensions/ArticleFeedbackv5/+/aa0e2e6dfe9e1004d145f2a787b59885688464c5/modules/jquery.articleFeedbackv5/jquery.articleFeedbackv5.js#710
Screenshot:
Example reproduction steps:
- Use ?uselang=x-xss on a page that has feedback enabled
System message: pipe-separator
Cause: https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/extensions/ArticleFeedbackv5/+/aa0e2e6dfe9e1004d145f2a787b59885688464c5/modules/jquery.articleFeedbackv5/jquery.articleFeedbackv5.js#1312
Screenshot:
Example reproduction steps:
- Add to common.css:
#siteSub { display: block; }
- Add to LocalSettings.php:
$wgArticleFeedbackv5LinkBuckets['buckets']['X'] = 0; $wgArticleFeedbackv5LinkBuckets['buckets']['A'] = 100;
- Clear your cookies because you're way too lazy to wait for the chosen bucket to expire lol
- Use ?uselang=x-xss on a page that has feedback enabled
Example reproduction steps:
- Add to common.css:
#siteSub { display: block; }
- Add to LocalSettings.php:
$wgArticleFeedbackv5LinkBuckets['buckets']['X'] = 0; $wgArticleFeedbackv5LinkBuckets['buckets']['A'] = 100;
- Add XSS to the system message articlefeedbackv5-disable-preference
- Clear your cookies because you're way too lazy to wait for the chosen bucket to expire lol
- Go to a page with feedback enabled
- Hover over the "Improve this page" link in the site subtitle
- Click on the subsequent [x]
Example reproduction steps:
- Add to LocalSettings.php:
$wgArticleFeedbackv5ThrottleThresholdPostsPerHour = 0;
- Add XSS to the system message articlefeedbackv5-error-throttled
- Go to a page with feedback enabled
- Try to leave some feedback
System message: articlefeedbackv5-activity-feedback-info
Cause: https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/extensions/ArticleFeedbackv5/+/aa0e2e6dfe9e1004d145f2a787b59885688464c5/api/ApiViewActivityArticleFeedbackv5.php#106
Screenshot:
Example reproduction steps:
- Leave some feedback on a page
- Go to Special:ArticleFeedbackv5
- Mark feedback as inappropriate
- Request oversight on feedback
- Refresh page
- Find that comment again
- View activity





