CVE-2024-47841: Path traversal when loading stylesheets
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Path Traversal.This issue affects Mediawiki - CSS Extension: from 1.42.X before 1.42.2, from 1.41.X before 1.41.3, from 1.39.X before 1.39.9.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47841?
The severity of CVE-2024-47841 is considered to be high due to its potential to allow path traversal attacks.
How do I fix CVE-2024-47841?
To fix CVE-2024-47841, upgrade the Mediawiki CSS Extension to version 1.42.2 or later, 1.41.3 or later, or 1.39.9 or later.
Which versions of the Mediawiki CSS Extension are affected by CVE-2024-47841?
CVE-2024-47841 affects Mediawiki CSS Extension versions from 1.39.0 up to 1.39.9, 1.41.0 up to 1.41.3, and 1.42.0 up to 1.42.2.
What kind of vulnerability is CVE-2024-47841?
CVE-2024-47841 is classified as a Path Traversal vulnerability due to improper limitation of a pathname.
Who is impacted by CVE-2024-47841?
Any user utilizing the affected versions of the Mediawiki CSS Extension may be impacted by CVE-2024-47841.