CVE-2024-47612
LOWDataDump < 601688ee8e8808a23b102fa305b178f27cbd226d - Stored Cross-Site Scripting via Unescaped Interface Messages
Title source: llmDescription
DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). If these messages are edited (which requires the (editinterface) right by default), anyone who can view Special:DataDump (which requires the (view-dump) right by default) can be XSSed. This vulnerability is fixed with 601688ee8e8808a23b102fa305b178f27cbd226d.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/miraheze/DataDump/security/advisories/GHSA-h8x8-24c7-r2rj
Patch x_refsource_misc
https://github.com/miraheze/DataDump/commit/601688ee8e8808a23b102fa305b178f27cbd226d.patch
Various Sources x_refsource_misc
https://issue-tracker.miraheze.org/T12670
Scores
CVSS v3
3.5
EPSS
0.0031
EPSS Percentile
22.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
CWE-80
Status
published
Products (1)
miraheze/DataDump
< 601688ee8e8808a23b102fa305b178f27cbd226d
Published
Oct 02, 2024
Tracked Since
Feb 18, 2026