CVE-2024-47815

Source
https://cve.org/CVERecord?id=CVE-2024-47815
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47815.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-47815
Aliases
  • GHSA-9p36-hrmr-98r9
Published
2024-10-09T18:21:58.981Z
Modified
2025-12-05T06:41:24.501161Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L CVSS Calculator
Summary
Cross-site Scripting in IncidentReporting
Details

IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of them require elevated permissions. Some are available to anyone who has the editincidents right, some are available to those who can edit interface messages (typically administrators and interface admins), and one is available to those who can edit LocalSettings.php. These issues have been addressed in commit 43896a4 and all users are advised to upgrade. Users unable to upgrade should prevent access to the Special:IncidentReports page.

Database specific
{
    "cwe_ids": [
        "CWE-79",
        "CWE-80"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47815.json"
}
References

Affected packages

Git / github.com/miraheze/incidentreporting

Affected ranges

Type
GIT
Repo
https://github.com/miraheze/incidentreporting
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47815.json"