Cross-Site Scripting Vulnerability in MassMessage Extension of MediaWiki
CVE-2024-23176
5.4MEDIUM
What is CVE-2024-23176?
A vulnerability has been found in the MassMessage extension of MediaWiki prior to version 1.40.2. This issue arises when the Special:MassMessage?uselang=x-xss URL is accessed, where an insecure internationalization (i18n) key permits Cross-Site Scripting (XSS). Attackers can exploit this flaw to inject malicious scripts into webpages viewed by users, potentially leading to data theft or session hijacking.
Affected Version(s)
MassMessage 0 < 1.40.2
