First published: Sat Oct 05 2024(Updated: )
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects Mediawiki - CSS Extension: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.
Credit: c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | >=1.39.0<1.39.9 | |
MediaWiki | >=1.41.0<1.41.3 | |
MediaWiki | >=1.42.0<1.42.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47845 is classified as a medium severity vulnerability due to improper encoding or escaping of output in the Mediawiki - CSS Extension.
To remediate CVE-2024-47845, upgrade to Mediawiki - CSS Extension version 1.39.9 or later, 1.41.3 or later, or 1.42.2 or later.
CVE-2024-47845 affects Mediawiki - CSS Extension versions before 1.39.9, 1.41.3, and 1.42.2.
CVE-2024-47845 is an improper encoding or escaping of output vulnerability that can lead to code injection.
The software impacted by CVE-2024-47845 is the Wikimedia Foundation's Mediawiki - CSS Extension.