PT-2023-6729 · Mediawiki+2 · Mediawiki+2

Carlos Bello

·

Published

2023-09-25

·

Updated

2025-08-14

·

CVE-2023-3550

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MediaWiki version 1.40.0
Description The issue exists due to the lack of protection for the web page structure. A remote attacker with a low-privileged user account can exploit this by sending a malicious link to the instance administrator, allowing them to become an administrator if the instance administrator allows XML file uploads. This can lead to a security breach.
Recommendations For MediaWiki version 1.40.0, restrict access to XML file uploads to prevent exploitation until a patch is available. As a temporary workaround, consider disabling XML file uploads to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6419
ALT-PU-2024-11168
ALT-PU-2024-1228
BDU:2023-07505
BIT-MEDIAWIKI-2023-3550
CVE-2023-3550
DLA-3671-1
DSA-5520-1
MGASA-2024-0155

Affected Products

Alt Linux
Mediawiki
Red Os