ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the `columns` and `help` keys on the form descriptor. An attacker may exploit this and would have a cross site scripting attack vector. Exploiting this on-wiki requires the `(editinterface)` right. Users should apply the code changes in commits `886cc6b94`, `2ef0f50880`, and `6942e8b2c` to resolve this vulnerability. There are no known workarounds for this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-22470 ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the `columns` and `help` keys on the form descriptor. An attacker may exploit this and would have a cross site scripting attack vector. Exploiting this on-wiki requires the `(editinterface)` right. Users should apply the code changes in commits `886cc6b94`, `2ef0f50880`, and `6942e8b2c` to resolve this vulnerability. There are no known workarounds for this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Sep 2024 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Miraheze
Miraheze managewiki
CPEs cpe:2.3:a:miraheze:managewiki:*:*:*:*:*:*:*:*
Vendors & Products Miraheze
Miraheze managewiki

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-01T23:36:21.701Z

Reserved: 2024-02-05T14:14:46.378Z

Link: CVE-2024-25109

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.701Z

cve-icon NVD

Status : Modified

Published: 2024-02-09T23:15:10.057

Modified: 2024-11-21T09:00:16.393

Link: CVE-2024-25109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.