Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47612

Опубликовано: 02 окт. 2024
Источник: nvd
CVSS3: 3.5
EPSS Низкий

Описание

DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). If these messages are edited (which requires the (editinterface) right by default), anyone who can view Special:DataDump (which requires the (view-dump) right by default) can be XSSed. This vulnerability is fixed with 601688ee8e8808a23b102fa305b178f27cbd226d.

EPSS

Процентиль: 28%
0.00099
Низкий

3.5 Low

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 28%
0.00099
Низкий

3.5 Low

CVSS3

Дефекты

CWE-79