PT-2023-6729 · Mediawiki+2 · Mediawiki+2

·

CVE-2023-3550

·

Published

2023-09-25

·

Updated

2025-08-14

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MediaWiki version 1.40.0
Description The issue exists due to the lack of protection for the web page structure. A remote attacker with a low-privileged user account can exploit this by sending a malicious link to the instance administrator, allowing them to become an administrator if the instance administrator allows XML file uploads. This can lead to a security breach.
Recommendations For MediaWiki version 1.40.0, restrict access to XML file uploads to prevent exploitation until a patch is available. As a temporary workaround, consider disabling XML file uploads to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6419
ALT-PU-2024-11168
ALT-PU-2024-1228
BDU:2023-07505
BIT-MEDIAWIKI-2023-3550
CVE-2023-3550
DLA-3671-1
DSA-5520-1
MGASA-2024-0155

Affected Products

Alt Linux
Mediawiki
Red Os