PT-2024-12205 · Mediawiki · Mediawiki Cargo Extension

Published

2024-03-26

·

Updated

2024-08-02

·

CVE-2023-29134

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions MediaWiki Cargo extension versions through 1.39.3
Description An issue was discovered in the Cargo extension for MediaWiki, where there is mishandling of backticks to smartSplit.
Recommendations For MediaWiki Cargo extension versions through 1.39.3, update to a version that fixes the mishandling of backticks to smartSplit. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-29134

Affected Products

Mediawiki Cargo Extension