Description
WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a special page that lists all wikis on the wiki farm. However, the special page does not make any effort to escape the wiki name or description. Therefore, if a wiki sets its name and/or description to an XSS payload, the XSS will execute whenever the wiki is shown on Special:WikiDiscover. This issue has been patched with commit `2ce846dd93` and all users are advised to apply that patch. User unable to upgrade should block access to `Special:WikiDiscover`.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/miraheze/WikiDiscover/security/advisories/GHSA-wf48-rqx3-39mf
Patch x_refsource_misc
https://github.com/miraheze/WikiDiscover/commit/2ce846dd93ddb9ec86f7472c4d57fe71a09dc827
Issue Tracking, Product x_refsource_misc
https://issue-tracker.miraheze.org/T12697
Scores
CVSS v3
7.6
EPSS
0.0042
EPSS Percentile
62.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-80
CWE-79
Status
published
Products (1)
miraheze/wikidiscover
< 2024-10-06
Published
Oct 07, 2024
Tracked Since
Feb 18, 2026