← Back

CVE-2024-34500

nvd nist
Published: May 5, 2024Modified: Nov 4, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class.

Affected (4)

1 product
Mediawiki
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Before 1.39.6
From 1.40.0 to 1.40.2
From 1.41.0 to 1.41.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 40

Timeline

No history available yet.