SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2024-23176

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The MassMessage extension in MediaWiki versions prior to 1.40.2 is vulnerable to cross-site scripting (XSS) via the Special:MassMessage?uselang=x-xss URL, which can be exploited through the i18n key massmessage-form-page-help. This vulnerability could allow an attacker to execute arbitrary scripts in the context of a user's session, potentially compromising user data and session integrity. Organizations using affected versions of MediaWiki should prioritize patching this vulnerability to mitigate the risk of XSS attacks.

CVE
CVE-2024-23176
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%

Original NVD Description

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.