Medium severity5.4NVD Advisory· Published Jan 12, 2024· Updated Jun 17, 2026
CVE-2024-23178
CVE-2024-23178
Description
An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- MediaWiki/Phonosdescription
Patches
Vulnerability mechanics
References
2- phabricator.wikimedia.org/T349312nvdExploitPatchVendor Advisory
- lists.wikimedia.org/hyperkitty/list/mediawiki-announce%40lists.wikimedia.org/message/TDBUBCCOQJUT4SCHJNPHKQNPBUUETY52/nvdMailing ListRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.