CVE-2024-23174 Information

Description

An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14 1.36.x through 1.39.x before 1.39.6 and 1.40.x before 1.40.2. XSS can occur via the rev-deleted-user pagetriage-tags-quickfilter-label pagetriage-triage pagetriage-filter-date-range-format-placeholder pagetriage-filter-date-range-to pagetriage-filter-date-range-from pagetriage-filter-date-range-heading pagetriage-filter-set-button or pagetriage-filter-reset-button message.

Reference

https://phabricator.wikimedia.org/T347704 https://gerrit.wikimedia.org/r/c/mediawiki/extensions/PageTriage/+/989177

Share on: