CVE-2024-47845: CSS sanitizer used incorrectly, and is easily bypassed
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects Mediawiki - CSS Extension: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47845?
CVE-2024-47845 is classified as a medium severity vulnerability due to improper encoding or escaping of output in the Mediawiki - CSS Extension.
How do I fix CVE-2024-47845?
To remediate CVE-2024-47845, upgrade to Mediawiki - CSS Extension version 1.39.9 or later, 1.41.3 or later, or 1.42.2 or later.
Which versions are affected by CVE-2024-47845?
CVE-2024-47845 affects Mediawiki - CSS Extension versions before 1.39.9, 1.41.3, and 1.42.2.
What type of vulnerability is CVE-2024-47845?
CVE-2024-47845 is an improper encoding or escaping of output vulnerability that can lead to code injection.
Which software is impacted by CVE-2024-47845?
The software impacted by CVE-2024-47845 is the Wikimedia Foundation's Mediawiki - CSS Extension.