CVE-2024-47815
CVSS 3.1 Score 6 of 10 (medium)
Details
Summary
CVE-2024-47815 is a Cross-site Scripting (XSS) vulnerability affecting the IncidentReporting MediaWiki extension. This extension is used for moving incident reports from wikitext to database tables. The vulnerability encompasses several issues, each requiring varying levels of permissions. Some XSS flaws are accessible to users with the `editincidents` right, while others can be exploited by those who can edit interface messages, usually reserved for administrators and interface admins. A more serious issue is found in the LocalSettings.php file, accessible to those with edit access. These vulnerabilities have been resolved in commit `43896a4`, and users are advised to upgrade as soon as possible to mitigate the risk. For those unable to upgrade, access to the Special:IncidentReports page should be restricted.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.