6.1
CVSSv3

CVE-2024-23179

Published: 12/01/2024 Updated: 18/01/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in the GlobalBlocking extension in MediaWiki prior to 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki