CVE-2024-47782

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 7, 2024
Updated: Nov 14, 2024
CWE ID 79
CWE ID 80

Summary

CVE-2024-47782 is a vulnerability affecting the WikiDiscover extension for CreateWiki managed farms. The special page, Special:WikiDiscover, which lists all wikis on the farm, fails to properly escape user-supplied wiki names and descriptions. Consequently, if a wiki is set to contain an XSS payload, the attack will be executed whenever the wiki is displayed on Special:WikiDiscover. The vulnerability has been mitigated with commit `2ce846dd93` and users are advised to apply the patch. For those unable to upgrade, blocking access to Special:WikiDiscover is recommended.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share