CVE-2024-47812

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Oct 9, 2024
Updated: Oct 10, 2024
CWE ID 79
CWE ID 80

Summary

CVE-2024-47812 is a vulnerability affecting the ImportDump MediaWiki extension, which allows anyone with the ability to edit interface strings to inject XSS payloads in messages for dates. This can potentially be exploited to XSS users who view the Special:RequestImportQueue page. The issue has been patched in commit `d054b95`, and it's recommended that all users apply this fix. For those unable to upgrade, alternative measures include preventing access to the ImportRequestQueue page on all wikis or protecting affected messages up to an interface administrator level on the global wiki. However, users with such rights can already edit Javascript pages, rendering the XSS attack virtually ineffective.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share