CVE-2024-34500

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
05/05/2024
Last modified:
11/06/2025

Description

An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.39.6 (excluding)
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.40.0 (including) 1.40.2 (excluding)
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.41.0 (including) 1.41.1 (excluding)
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*