CVE-2024-25109: Cross-Site Scripting in the extensions, settings, permissions and namespaces subpages of ManageWiki
ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the columns and help keys on the form descriptor. An attacker may exploit this and would have a cross site scripting attack vector. Exploiting this on-wiki requires the (editinterface) right. Users should apply the code changes in commits 886cc6b94, 2ef0f50880, and 6942e8b2c to resolve this vulnerability. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MediaWiki extension: ManageWikito a version that resolves this vulnerability.Patch 886cc6b94 - Upgrade
Upgrade
MediaWiki extension: ManageWikito a version that resolves this vulnerability.Patch 2ef0f50880 - Upgrade
Upgrade
MediaWiki extension: ManageWikito a version that resolves this vulnerability.Patch 6942e8b2c
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25109?
CVE-2024-25109 has been assigned a moderate severity level due to the potential for cross-site scripting exploitation.
How do I fix CVE-2024-25109?
To fix CVE-2024-25109, ensure you are using an updated version of the Miraheze ManageWiki extension released after February 9, 2024.
Who is affected by CVE-2024-25109?
CVE-2024-25109 affects users of the Miraheze ManageWiki extension prior to the fix on February 9, 2024.
What types of attacks can CVE-2024-25109 facilitate?
CVE-2024-25109 can facilitate cross-site scripting (XSS) attacks through improperly escaped interface messages.
Is CVE-2024-25109 a critical vulnerability?
No, CVE-2024-25109 is not classified as a critical vulnerability, but it should still be addressed promptly to avoid potential exploitation.