CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user can insert arbitrary HTML that is displayed in the request wiki queue when requesting a wiki. If a wiki creator comes across the XSS payload, their user session can be abused to retrieve deleted wiki requests, which typically contains private information. Likewise, this can also be abused on those with the ability to suppress requests to view sensitive information. This issue has been patched with commit `693a220` and all users are advised to apply the patch. Users unable to upgrade should disable Javascript and/or prevent access to the vulnerable page (Special:RequestWikiQueue).
History

Thu, 14 Nov 2024 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Miraheze
Miraheze createwiki
CPEs cpe:2.3:a:miraheze:createwiki:*:*:*:*:*:*:*:*
Vendors & Products Miraheze
Miraheze createwiki
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 08 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Oct 2024 21:45:00 +0000

Type Values Removed Values Added
Description CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user can insert arbitrary HTML that is displayed in the request wiki queue when requesting a wiki. If a wiki creator comes across the XSS payload, their user session can be abused to retrieve deleted wiki requests, which typically contains private information. Likewise, this can also be abused on those with the ability to suppress requests to view sensitive information. This issue has been patched with commit `693a220` and all users are advised to apply the patch. Users unable to upgrade should disable Javascript and/or prevent access to the vulnerable page (Special:RequestWikiQueue).
Title Cross-site Scripting (XSS) in Special:RequestWikiQueue when displaying sitename in CreateWiki
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-07T21:30:23.058Z

Updated: 2024-10-08T14:13:28.705Z

Reserved: 2024-09-30T21:28:53.236Z

Link: CVE-2024-47781

cve-icon Vulnrichment

Updated: 2024-10-08T14:13:22.728Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-07T22:15:03.133

Modified: 2024-11-14T18:19:28.180

Link: CVE-2024-47781

cve-icon Redhat

No data.