PT-2024-2679 · Mediawiki+2 · Watchanalytics Extension+3

Ashley

·

Published

2024-01-12

·

Updated

2025-06-19

·

CVE-2024-23177

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.40.2 WatchAnalytics extension in MediaWiki (affected versions not specified)
Description An issue in the WatchAnalytics extension allows for XSS to occur via the Special:PageStatistics page parameter. This can enable a remote attacker to perform cross-site scripting attacks.
Recommendations For MediaWiki versions prior to 1.40.2, update to version 1.40.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Special:PageStatistics page until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5905
BDU:2024-02788
BIT-MEDIAWIKI-2024-23177
CVE-2024-23177

Affected Products

Alt Linux
Mediawiki
Red Os
Watchanalytics Extension