CVE-2024-40599: XSS
Published Jul 6, 2024
·Updated
An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
Affected Software
1 affected component
MediaWiki MediaWiki<=1.42.1
Event History
Jul 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jul 7, 2024
Data Sourced
via NVD·12:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-40599?
CVE-2024-40599 has been classified as a high severity vulnerability due to its potential for executing stored cross-site scripting (XSS).
2
How do I fix CVE-2024-40599?
To fix CVE-2024-40599, upgrade MediaWiki to a version later than 1.42.1 where the issue has been patched.
3
What software is affected by CVE-2024-40599?
CVE-2024-40599 affects MediaWiki versions up to and including 1.42.1.
4
What impact does CVE-2024-40599 have on users?
CVE-2024-40599 allows attackers to inject malicious scripts into the sidebar, potentially compromising user sessions and site security.
5
Is there a workaround for CVE-2024-40599?
As of now, there are no known workarounds for CVE-2024-40599 other than upgrading to a secure version of MediaWiki.