PT-2024-2679 · Mediawiki+2 · Watchanalytics Extension+3
Ashley
·
Published
2024-01-12
·
Updated
2025-06-19
·
CVE-2024-23177
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki versions prior to 1.40.2
WatchAnalytics extension in MediaWiki (affected versions not specified)
Description
An issue in the WatchAnalytics extension allows for XSS to occur via the Special:PageStatistics page parameter. This can enable a remote attacker to perform cross-site scripting attacks.
Recommendations
For MediaWiki versions prior to 1.40.2, update to version 1.40.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Special:PageStatistics page until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Mediawiki
Red Os
Watchanalytics Extension