U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-47782

Change History

New CVE Received from GitHub, Inc. 10/07/2024 6:15:03 PM

Action Type Old Value New Value
Added Description

								
							
							
						
WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a special page that lists all wikis on the wiki farm. However, the special page does not make any effort to escape the wiki name or description. Therefore, if a wiki sets its name and/or description to an XSS payload, the XSS will execute whenever the wiki is shown on Special:WikiDiscover. This issue has been patched with commit `2ce846dd93` and all users are advised to apply that patch. User unable to upgrade should block access to `Special:WikiDiscover`.
Added CVSS V3.1

								
							
							
						
GitHub, Inc. AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Added CWE

								
							
							
						
GitHub, Inc. CWE-79
Added CWE

								
							
							
						
GitHub, Inc. CWE-80
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/miraheze/WikiDiscover/commit/2ce846dd93ddb9ec86f7472c4d57fe71a09dc827 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/miraheze/WikiDiscover/security/advisories/GHSA-wf48-rqx3-39mf [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://issue-tracker.miraheze.org/T12697 [No types assigned]