← Back

CVE-2024-47782

nvd nist
Published: Oct 7, 2024Modified: Nov 14, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a special page that lists all wikis on the wiki farm. However, the special page does not make any effort to escape the wiki name or description. Therefore, if a wiki sets its name and/or description to an XSS payload, the XSS will execute whenever the wiki is shown on Special:WikiDiscover. This issue has been patched with commit `2ce846dd93` and all users are advised to apply that patch. User unable to upgrade should block access to `Special:WikiDiscover`.

Affected (1)

1 product
Wikidiscover
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2024-10-06

References (3)

Source: security-advisories@github.com
Issue TrackingProduct

Timeline

No history available yet.