CVE-2024-25109: Cross-Site Scripting in the extensions, settings, permissions and namespaces subpages of ManageWiki

Published Feb 9, 2024
·
Updated

ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the columns and help keys on the form descriptor. An attacker may exploit this and would have a cross site scripting attack vector. Exploiting this on-wiki requires the (editinterface) right. Users should apply the code changes in commits 886cc6b94, 2ef0f50880, and 6942e8b2c to resolve this vulnerability. There are no known workarounds for this vulnerability.

Affected Software

1 affected component
Miraheze ManageWiki<2024-02-09

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MediaWiki extension: ManageWiki to a version that resolves this vulnerability.

    Patch 886cc6b94
  2. Upgrade

    Upgrade MediaWiki extension: ManageWiki to a version that resolves this vulnerability.

    Patch 2ef0f50880
  3. Upgrade

    Upgrade MediaWiki extension: ManageWiki to a version that resolves this vulnerability.

    Patch 6942e8b2c

Event History

Feb 9, 2024
CVE Published
via MITRE·10:25 PM
Data Sourced
via MITRE·10:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-25109?

CVE-2024-25109 has been assigned a moderate severity level due to the potential for cross-site scripting exploitation.

2

How do I fix CVE-2024-25109?

To fix CVE-2024-25109, ensure you are using an updated version of the Miraheze ManageWiki extension released after February 9, 2024.

3

Who is affected by CVE-2024-25109?

CVE-2024-25109 affects users of the Miraheze ManageWiki extension prior to the fix on February 9, 2024.

4

What types of attacks can CVE-2024-25109 facilitate?

CVE-2024-25109 can facilitate cross-site scripting (XSS) attacks through improperly escaped interface messages.

5

Is CVE-2024-25109 a critical vulnerability?

No, CVE-2024-25109 is not classified as a critical vulnerability, but it should still be addressed promptly to avoid potential exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203