PT-2024-32824 · Mediawiki · Importdump
Universal-Omega
·
Published
2024-10-09
·
Updated
2024-10-10
·
CVE-2024-47812
CVSS v3.1
6.0
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
ImportDump extension for mediawiki (affected versions not specified)
Description
The issue allows anyone who can edit the interface strings of a wiki, typically administrators and interface admins, to embed XSS payloads in the messages for dates. This can lead to XSS attacks on users who view Special:RequestImportQueue. The problem has been patched in commit
d054b95.Recommendations
Apply the commit
d054b95 to your branch to patch the issue.
If unable to upgrade, prevent access to Special:RequestImportQueue on all wikis, except for the global wiki, and protect the affected messages up to the interface administrator level on the global wiki, if available.
Alternatively, prevent access to Special:RequestImportQueue altogether.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Importdump