CVE-2024-34507

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)

Published: May 5, 2024 / Updated: 6mo ago

010
CVSS 7.4EPSS 0.04%High
CVE info copied to clipboard

Summary

An XSS vulnerability exists in MediaWiki before versions 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1 due to improper handling of the 0x1b character in includes/CommentFormatter/CommentParser.php. An attacker can inject malicious scripts into Special:RecentChanges by sending a crafted 0x1b character sequence.

Impact

This vulnerability could allow an attacker to execute arbitrary script in the context of the vulnerable MediaWiki site. Impact includes theft of user credentials, website defacement, spreading malware to users, and potentially full server compromise if the MediaWiki software is running with elevated privileges.

Exploitation

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patch

Yes, patched versions of MediaWiki are available - 1.39.7, 1.40.3 and 1.41.1. Upgrading to these fixed releases will resolve the issue.

Mitigation

Until patched versions can be installed, apply strict input validation and output encoding on user-supplied data rendered in web pages. Web application firewalls may also help detect and block attempted XSS attacks.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Timeline

CVE Assignment

NVD published the first details for CVE-2024-34507

May 5, 2024 at 7:15 PM
First Article

Feedly found the first article mentioning CVE-2024-34507. See article

May 5, 2024 at 7:24 PM / National Vulnerability Database
CVSS Estimate

Feedly estimated the CVSS score as MEDIUM

May 5, 2024 at 7:24 PM
Vendor Advisory

RedHat CVE advisory released a security advisory (CVE-2024-34507).

May 6, 2024 at 4:30 AM
CVSS

A CVSS base score of 5.3 has been assigned.

May 6, 2024 at 4:30 AM / redhat-cve-advisories
EPSS

EPSS Score was set to: 0.04% (Percentile: 8.3%)

May 6, 2024 at 9:58 AM
Detection in Vulnerability Scanners

Detection for the vulnerability has been added to Nessus (195321)

May 11, 2024 at 9:15 AM
CVSS

A CVSS base score of 7.4 has been assigned.

Jul 3, 2024 at 2:24 AM / nvd
Detection in Vulnerability Scanners

Detection for the vulnerability has been added to Qualys (285781)

Jul 22, 2024 at 7:53 AM
Static CVE Timeline Graph

Affected Systems

Mediawiki/mediawiki
+null more

Patches

bugzilla.redhat.com
+null more

Attack Patterns

CAPEC-209: XSS Using MIME Type Mismatch
+null more

CVSS V3.1

Attack Vector:Network
Attack Complexity:Low
Privileges Required:None
User Interaction:Required
Scope:Changed
Confidentiality:High
Integrity:None
Availability Impact:None

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI