Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2024-34507
HistoryMay 05, 2024 - 7:15 p.m.

CVE-2024-34507

2024-05-0519:15:07
Debian Security Bug Tracker
security-tracker.debian.org
7
xss vulnerability
mediawiki
1.39.7
1.40.3
1.41.1

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%

An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%