CVE-2024-47782
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-47782 is a vulnerability affecting the WikiDiscover extension for CreateWiki managed farms. The special page, Special:WikiDiscover, which lists all wikis on the farm, fails to properly escape user-supplied wiki names and descriptions. Consequently, if a wiki is set to contain an XSS payload, the attack will be executed whenever the wiki is displayed on Special:WikiDiscover. The vulnerability has been mitigated with commit `2ce846dd93` and users are advised to apply the patch. For those unable to upgrade, blocking access to Special:WikiDiscover is recommended.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.