CVE-2024-23176: XSS
An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
MediaWiki installations using the MassMessage extension are affected if they run a version before 1.40.2.
What does an attacker need to exploit this issue?
The attacker needs at least low-level privileges and must persuade a user to visit a crafted Special:MassMessage URL containing a uselang=x-xss parameter.
What is the impact of successful exploitation?
Successful exploitation enables cross-site scripting through the massmessage-form-page-help i18n key. The provided vector indicates low confidentiality and integrity impact, with no availability impact.
What should be prioritized for remediation?
Update the affected MediaWiki MassMessage extension to version 1.40.2 or later. The provided information does not describe an alternative mitigation.