CVE-2024-47612

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Oct 2, 2024
Updated: Oct 4, 2024
CWE ID 79
CWE ID 80

Summary

CVE-2024-47612 is a MediaWiki vulnerability affecting the DataDump extension. Unescaped interface messages, namely (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), and (datadump-table-column-failed), can be exploited through XSS attacks. Editing these messages, which requires the (editinterface) right by default, poses a risk to users who can access Special:DataDump, necessitating the (view-dump) right. This issue is resolved with the commit 601688ee8e8808a23b102fa305b178f27cbd226d.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share