CVE-2024-47612

DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). If these messages are edited (which requires the (editinterface) right by default), anyone who can view Special:DataDump (which requires the (view-dump) right by default) can be XSSed. This vulnerability is fixed with 601688ee8e8808a23b102fa305b178f27cbd226d.
Configurations

No configuration.

History

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) DataDump es una extensión de MediaWiki que proporciona volcados de wikis. Varios mensajes de interfaz no tienen caracteres de escape (más específicamente, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). Si se editan estos mensajes (lo que requiere el derecho (editinterface) de forma predeterminada), cualquiera que pueda ver Special:DataDump (que requiere el derecho (view-dump) de forma predeterminada) puede ser víctima de XSS. Esta vulnerabilidad se corrige con 601688ee8e8808a23b102fa305b178f27cbd226d.

02 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-02 15:15

Updated : 2024-10-04 13:50


NVD link : CVE-2024-47612

Mitre link : CVE-2024-47612

CVE.ORG link : CVE-2024-47612


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)