Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23172


An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via message definitions. e.g., in SpecialCheckUserLog.


Published

2024-01-12T05:15:10.187

Last Modified

2025-06-04T16:15:29.090

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mediawiki mediawiki < 1.35.14 Yes
Application mediawiki mediawiki < 1.39.6 Yes
Application mediawiki mediawiki < 1.40.2 Yes

References