PT-2023-6729 · Mediawiki+2 · Mediawiki+2
Carlos Bello
·
Published
2023-09-25
·
Updated
2025-08-14
·
CVE-2023-3550
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MediaWiki version 1.40.0
Description
The issue exists due to the lack of protection for the web page structure. A remote attacker with a low-privileged user account can exploit this by sending a malicious link to the instance administrator, allowing them to become an administrator if the instance administrator allows XML file uploads. This can lead to a security breach.
Recommendations
For MediaWiki version 1.40.0, restrict access to XML file uploads to prevent exploitation until a patch is available. As a temporary workaround, consider disabling XML file uploads to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Mediawiki
Red Os