PT-2024-32824 · Mediawiki · Importdump

Universal-Omega

·

Published

2024-10-09

·

Updated

2024-10-10

·

CVE-2024-47812

CVSS v3.1

6.0

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions ImportDump extension for mediawiki (affected versions not specified)
Description The issue allows anyone who can edit the interface strings of a wiki, typically administrators and interface admins, to embed XSS payloads in the messages for dates. This can lead to XSS attacks on users who view Special:RequestImportQueue. The problem has been patched in commit d054b95.
Recommendations Apply the commit d054b95 to your branch to patch the issue. If unable to upgrade, prevent access to Special:RequestImportQueue on all wikis, except for the global wiki, and protect the affected messages up to the interface administrator level on the global wiki, if available. Alternatively, prevent access to Special:RequestImportQueue altogether.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-47812
GHSA-465H-45V4-6FX9

Affected Products

Importdump