Stored XSS leads to privilege escalation in MediaWiki v1.40.0
CVE-2023-3550
7.3HIGH
What is CVE-2023-3550?
MediaWiki version 1.40.0 has a security vulnerability that arises from insufficient validation of namespaces in XML file uploads. If XML uploads are permitted by the instance administrator, a remote attacker with low privileges can exploit this weakness. By sending a specially crafted link, the attacker may trick the instance administrator into triggering the exploit, leading to unauthorized administrative access.
Affected Version(s)
MediaWiki MacOS 1.40.0
