CVE-2024-47840: Stored XSS through sidebar in Apex skin
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediawiki - Apex skin: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47840?
CVE-2024-47840 is classified as a serious vulnerability due to its potential for Stored Cross-site Scripting (XSS).
How do I fix CVE-2024-47840?
To fix CVE-2024-47840, upgrade to Mediawiki - Apex skin versions 1.39.9, 1.41.3, or 1.42.2 or later.
Which versions of Mediawiki - Apex skin are affected by CVE-2024-47840?
CVE-2024-47840 affects Mediawiki - Apex skin versions prior to 1.39.9, 1.41.3, and 1.42.2.
What does Cross-site Scripting (XSS) mean in the context of CVE-2024-47840?
In the context of CVE-2024-47840, Cross-site Scripting (XSS) allows attackers to inject malicious scripts into web pages viewed by other users.
What is the impact of CVE-2024-47840 if exploited?
If exploited, CVE-2024-47840 can allow unauthorized access to user data and execute arbitrary scripts in the context of the victim's browser.