CVE-2024-47847
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-47847 is a Cross-Site Scripting (XSS) vulnerability affecting the Mediawiki - Cargo extension from versions 3.6.X before 3.6.1. The Wikimedia Foundation's Mediawiki software, which includes Cargo, failed to properly neutralize user-supplied input during web page generation, allowing attackers to inject malicious scripts. An attacker could exploit this vulnerability to steal user data, manipulate web pages, or carry out other malicious activities. Users are advised to update their Mediawiki - Cargo installations to the latest version to mitigate the risk of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mediawiki - Cargo
Affected Vendors
- Mediawiki