CVE-2023-3550
CVSS V2 None
CVSS V3 None
Description
Mediawiki v1.40.0 does not validate namespaces used in XML files.
Therefore, if the instance administrator allows XML file uploads,
a remote attacker with a low-privileged user account can use this
exploit to become an administrator by sending a malicious link to
the instance administrator.
Overview
- CVE ID
- CVE-2023-3550
- Assigner
- Fluid Attacks
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-09-25T15:20:27.351Z
- Last Modified Date
- 2023-09-25T15:20:27.351Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-3550 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3550 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 20:15:57 | Added to TrackCVE |