Medium severity6.1NVD Advisory· Published Jan 12, 2024· Updated Jun 17, 2026
CVE-2024-23179
CVE-2024-23179
Description
An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- MediaWiki/GlobalBlockingdescription
- Range: <1.40.2
Patches
Vulnerability mechanics
References
2- lists.wikimedia.org/hyperkitty/list/mediawiki-announce%40lists.wikimedia.org/message/TDBUBCCOQJUT4SCHJNPHKQNPBUUETY52/nvdIssue TrackingPatchRelease Notes
- phabricator.wikimedia.org/T347746nvdExploitPatchVendor Advisory
News mentions
0No linked articles in our index yet.