CVE-2024-47816
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-47816 is a vulnerability affecting the ImportDump mediawiki extension. This extension, used for automating user import requests, stores local actor IDs in the database. If an attacker on another wiki shares the same ID as a user on the central wiki, they can masquerade as the original requester, leading to potential comments creation, request editing, and private request viewing. This issue has been resolved in commit `5c91dfc`, and all users are encouraged to update. Those unable to update can disable the special page on their global wiki as a workaround. More information can be found in the `miraheze/mw-config` repository at `e566499`.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.