Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-34507


An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.


Published

2024-05-05T19:15:07.307

Last Modified

2025-06-17T16:37:39.013

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-80

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mediawiki mediawiki < 1.39.7 Yes
Application mediawiki mediawiki < 1.40.3 Yes
Application mediawiki mediawiki < 1.41.1 Yes
Operating System fedoraproject fedora 40 Yes

References