Medium severity5.3NVD Advisory· Published Oct 4, 2024· Updated Jun 17, 2026
CVE-2024-47913
CVE-2024-47913
Description
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mediawiki/abuse-filterPackagist | < 1.39.9 | 1.39.9 |
mediawiki/abuse-filterPackagist | >= 1.40.0, < 1.41.3 | 1.41.3 |
mediawiki/abuse-filterPackagist | >= 1.42.0, < 1.42.2 | 1.42.2 |
Affected products
3- MediaWiki/AbuseFilter extensiondescription
Patches
Vulnerability mechanics
References
4- gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1076855nvdPatchVendor AdvisoryWEB
- phabricator.wikimedia.org/T372998nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-rmcp-9fhq-58pvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-47913ghsaADVISORY
News mentions
0No linked articles in our index yet.