Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42705 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediawiki - Apex skin: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2. |
Wed, 16 Oct 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wikimedia apex
|
|
| CPEs | cpe:2.3:a:wikimedia:apex:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wikimedia apex
|
|
| Metrics |
cvssV3_1
|
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wikimedia
Wikimedia mediawiki-apex Skin |
|
| CPEs | cpe:2.3:a:wikimedia:mediawiki-apex_skin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wikimedia
Wikimedia mediawiki-apex Skin |
|
| Metrics |
ssvc
|
Sat, 05 Oct 2024 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediawiki - Apex skin: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2. | |
| Title | Stored XSS through sidebar in Apex skin | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: wikimedia-foundation
Published:
Updated: 2024-10-07T17:15:49.923Z
Reserved: 2024-10-03T23:44:16.834Z
Link: CVE-2024-47840
Updated: 2024-10-07T17:15:42.340Z
Status : Analyzed
Published: 2024-10-05T01:15:12.107
Modified: 2024-10-16T16:44:54.440
Link: CVE-2024-47840
No data.
OpenCVE Enrichment
No data.
EUVD