CVE-2024-47612
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Oct 2, 2024
Updated: Oct 4, 2024
CWE ID 79
CWE ID 80
Summary
CVE-2024-47612 is a MediaWiki vulnerability affecting the DataDump extension. Unescaped interface messages, namely (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), and (datadump-table-column-failed), can be exploited through XSS attacks. Editing these messages, which requires the (editinterface) right by default, poses a risk to users who can access Special:DataDump, necessitating the (view-dump) right. This issue is resolved with the commit 601688ee8e8808a23b102fa305b178f27cbd226d.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.