CVE-2024-47812
CVSS 3.1 Score 6 of 10 (medium)
Details
Summary
CVE-2024-47812 is a vulnerability affecting the ImportDump MediaWiki extension, which allows anyone with the ability to edit interface strings to inject XSS payloads in messages for dates. This can potentially be exploited to XSS users who view the Special:RequestImportQueue page. The issue has been patched in commit `d054b95`, and it's recommended that all users apply this fix. For those unable to upgrade, alternative measures include preventing access to the ImportRequestQueue page on all wikis or protecting affected messages up to an interface administrator level on the global wiki. However, users with such rights can already edit Javascript pages, rendering the XSS attack virtually ineffective.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.