Stored XSS leads to privilege escalation in MediaWiki v1.40.0
Vulnerability Description
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-3550
Credits & Attribution
No credits recorded in the NVD database.
References
- https://fluidattacks.com/advisories/blondie/
- https://www.mediawiki.org/wiki/MediaWiki/
- https://www.debian.org/security/2023/dsa-5520
- https://lists.debian.org/debian-lts-announce/2023/11/msg00027.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/
Affected Vendor
MediaWiki
View all reports →