PT-2024-2676 · Mediawiki+2 · Mediawiki+2

·

CVE-2024-23172

·

Published

2024-01-12

·

Updated

2025-06-19

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.14 MediaWiki versions 1.36.x through 1.39.x before 1.39.6 MediaWiki versions 1.40.x before 1.40.2
Description An issue in the CheckUser extension allows XSS to occur via message definitions, for example, in SpecialCheckUserLog. This can enable a remote attacker to perform cross-site scripting attacks.
Recommendations For versions prior to 1.35.14, update to version 1.35.14 or later. For versions 1.36.x through 1.39.x, update to version 1.39.6 or later. For versions 1.40.x, update to version 1.40.2 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5905
BDU:2024-02785
BIT-MEDIAWIKI-2024-23172
CVE-2024-23172

Affected Products

Alt Linux
Mediawiki
Red Os