Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-36123

Опубликовано: 03 июн. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 5.4
EPSS Низкий

Описание

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page MediaWiki:Tagline has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the editinterface permission, or sysops). This vulnerability is fixed in 2.16.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:starcitizen.tools:citizen:*:*:*:*:*:mediawiki:*:*
Версия до 2.16.0 (исключая)

EPSS

Процентиль: 62%
0.00424
Низкий

6.5 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the `editinterface` permission, or sysops). This vulnerability is fixed in 2.16.0.

EPSS

Процентиль: 62%
0.00424
Низкий

6.5 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79