Lucene search

K
nvd[email protected]NVD:CVE-2024-34507
HistoryMay 05, 2024 - 7:15 p.m.

CVE-2024-34507

2024-05-0519:15:07
CWE-80
web.nvd.nist.gov
2
xss vulnerability
mediawiki
version 1.39.7
version 1.40.3
version 1.41.1

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%

An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%