CVE-2024-47816

CVSS 3.1 Score 6.4 of 10 (medium)

Integrity high
Attack Complexity high
Confidentiality low
Availability low
Privileges Required low
Scope unchanged

Details

Published Oct 9, 2024
Updated: Oct 10, 2024
CWE ID 282

Summary

CVE-2024-47816 is a vulnerability affecting the ImportDump mediawiki extension. This extension, used for automating user import requests, stores local actor IDs in the database. If an attacker on another wiki shares the same ID as a user on the central wiki, they can masquerade as the original requester, leading to potential comments creation, request editing, and private request viewing. This issue has been resolved in commit `5c91dfc`, and all users are encouraged to update. Those unable to update can disable the special page on their global wiki as a workaround. More information can be found in the `miraheze/mw-config` repository at `e566499`.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share