Executive Summary

Informations
Name CVE-2024-47816 First vendor Publication 2024-10-09
Vendor Cve Last vendor Modification 2024-10-10

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the central wiki, the user on the other wiki can act as if they're the original wiki requester. This can be abused to create new comments, edit the request, and view the request if it's marked private. This issue has been addressed in commit `5c91dfc` and all users are advised to update. Users unable to update may disable the special page outside of their global wiki. See `miraheze/mw-config@e566499` for details on that.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47816

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-282 Improper Ownership Management

Sources (Detail)

https://github.com/miraheze/ImportDump/commit/5c91dfce78320e717516ee65ef5a05f...
https://github.com/miraheze/ImportDump/security/advisories/GHSA-jjmq-mg36-6387
https://github.com/miraheze/mw-config/commit/e5664995fbb8644f9a80b450b4326194...
https://issue-tracker.miraheze.org/T12701
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2024-10-10 17:27:27
  • Multiple Updates
2024-10-10 00:27:27
  • First insertion