Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-34502


An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.


Published

2024-05-05T19:15:07.197

Last Modified

2025-06-17T14:53:28.127

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mediawiki mediawiki < 1.39.6 Yes
Application mediawiki mediawiki < 1.40.2 Yes
Application mediawiki mediawiki < 1.41.1 Yes
Operating System fedoraproject fedora 40 Yes

References