CVE-2024-23172: XSS
An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via message definitions. e.g., in SpecialCheckUserLog.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23172?
CVE-2024-23172 has been classified as a medium severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2024-23172?
To fix CVE-2024-23172, upgrade your MediaWiki installation to version 1.35.14 or later, or to 1.39.6 or later if using versions 1.36.x or 1.40.x.
What versions of MediaWiki are affected by CVE-2024-23172?
CVE-2024-23172 affects MediaWiki versions prior to 1.35.14, between 1.36.0 and 1.39.6, and between 1.40.0 and 1.40.2.
What type of vulnerability is CVE-2024-23172?
CVE-2024-23172 is classified as a cross-site scripting (XSS) vulnerability.
Is there a workaround for CVE-2024-23172 if I cannot upgrade?
There is no official workaround for CVE-2024-23172, so upgrading to a patched version is strongly recommended.