CVE-2024-47849

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 5, 2024
Updated: Oct 16, 2024
CWE ID 89

Summary

CVE-2024-47849 is an SQL Injection vulnerability affecting the Mediawiki - Cargo extension, specifically versions 3.6.X before 3.6.1. This issue arises due to improper neutralization of special elements in SQL commands, enabling attackers to inject malicious code and potentially gain unauthorized access to sensitive data or even take control of the affected system. The Wikimedia Foundation's Mediawiki software is susceptible to this vulnerability, posing a significant risk to sites utilizing the Cargo extension. Organizations using these versions are urged to update immediately to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share