CVE-2023-3550
published 2023-09-25CVE-2023-3550: Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a…
PriorityP348critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
1.15%
63.4th percentile
Mediawiki v1.40.0 does not validate namespaces used in XML files.
Therefore, if the instance administrator allows XML file uploads,
a remote attacker with a low-privileged user account can use this
exploit to become an administrator by sending a malicious link to
the instance administrator.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.39.5-1~deb12u1 (bookworm) | mediawiki 1:1.39.5-1~deb12u1 (bookworm) |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.35.13-1~deb11u1 | 1:1.35.13-1~deb11u1 |
| mediawiki | mediawiki | >= 0 < 1:1.39.5-1~deb12u1 | 1:1.39.5-1~deb12u1 |
| mediawiki | mediawiki | >= 0 < 1:1.39.5-1 | 1:1.39.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.39.5-1 | 1:1.39.5-1 |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
osv9.0CRITICAL
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mediawiki: stored XSS leads to privilege escalation
vendor_redhat·2023-09-25·CVSS 7.3
CVE-2023-3550 [HIGH] CWE-79 mediawiki: stored XSS leads to privilege escalation
mediawiki: stored XSS leads to privilege escalation
Mediawiki v1.40.0 does not validate namespaces used in XML files.
Therefore, if the instance administrator allows XML file uploads,
a remote attacker with a low-privileged user account can use this
exploit to become an administrator by sending a malicious link to
the instance administrator.
Package: mediawiki (Red Hat OpenShift Container Platform 3.11) - Out of support scope
Debian
CVE-2023-3550: mediawiki - Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if...
vendor_debian·2023·CVSS 7.3
CVE-2023-3550 [HIGH] CVE-2023-3550: mediawiki - Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if...
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.
Scope: local
bookworm: resolved (fixed in 1:1.39.5-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.13-1~deb11u1)
forky: resolved (fixed in 1:1.39.5-1)
sid: resolved (fixed in 1:1.39.5-1)
trixie: resolved (fixed in 1:1.39.5-1)
OSV
CVE-2023-3550: Mediawiki v1
osv·2023-09-25·CVSS 9.0
CVE-2023-3550 [CRITICAL] CVE-2023-3550: Mediawiki v1
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.
GHSA
MediaWiki malicious XML upload leads to privilege escalation
ghsa_unreviewed·2023-09-25
CVE-2023-3550 [HIGH] CWE-79 MediaWiki malicious XML upload leads to privilege escalation
MediaWiki malicious XML upload leads to privilege escalation
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://fluidattacks.com/advisories/blondie/https://lists.debian.org/debian-lts-announce/2023/11/msg00027.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/https://www.debian.org/security/2023/dsa-5520https://www.mediawiki.org/wiki/MediaWiki/https://fluidattacks.com/advisories/blondie/https://lists.debian.org/debian-lts-announce/2023/11/msg00027.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/https://www.debian.org/security/2023/dsa-5520https://www.mediawiki.org/wiki/MediaWiki/
2023-09-25
Published