Description
ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the `columns` and `help` keys on the form descriptor. An attacker may exploit this and would have a cross site scripting attack vector. Exploiting this on-wiki requires the `(editinterface)` right. Users should apply the code changes in commits `886cc6b94`, `2ef0f50880`, and `6942e8b2c` to resolve this vulnerability. There are no known workarounds for this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22470 | ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the `columns` and `help` keys on the form descriptor. An attacker may exploit this and would have a cross site scripting attack vector. Exploiting this on-wiki requires the `(editinterface)` right. Users should apply the code changes in commits `886cc6b94`, `2ef0f50880`, and `6942e8b2c` to resolve this vulnerability. There are no known workarounds for this vulnerability. |
References
History
Thu, 05 Sep 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Miraheze
Miraheze managewiki |
|
| CPEs | cpe:2.3:a:miraheze:managewiki:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Miraheze
Miraheze managewiki |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-01T23:36:21.701Z
Reserved: 2024-02-05T14:14:46.378Z
Link: CVE-2024-25109
Updated: 2024-08-01T23:36:21.701Z
Status : Modified
Published: 2024-02-09T23:15:10.057
Modified: 2024-11-21T09:00:16.393
Link: CVE-2024-25109
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD