PT-2024-2676 · Mediawiki+2 · Mediawiki+2

Dreamy_Jazz

·

Published

2024-01-12

·

Updated

2025-06-19

·

CVE-2024-23172

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.14 MediaWiki versions 1.36.x through 1.39.x before 1.39.6 MediaWiki versions 1.40.x before 1.40.2
Description An issue in the CheckUser extension allows XSS to occur via message definitions, for example, in SpecialCheckUserLog. This can enable a remote attacker to perform cross-site scripting attacks.
Recommendations For versions prior to 1.35.14, update to version 1.35.14 or later. For versions 1.36.x through 1.39.x, update to version 1.39.6 or later. For versions 1.40.x, update to version 1.40.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5905
BDU:2024-02785
BIT-MEDIAWIKI-2024-23172
CVE-2024-23172

Affected Products

Alt Linux
Mediawiki
Red Os