Summary
Detail | |||
---|---|---|---|
Vendor | Mediawiki | First view | 2024-10-05 |
Product | Cargo | Last view | 2024-10-05 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:a:mediawiki:cargo:3.6.0:*:*:*:*:*:*:* | 3 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
9.8 | 2024-10-05 | CVE-2024-47849 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1. |
6.1 | 2024-10-05 | CVE-2024-47847 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1. |
8.8 | 2024-10-05 | CVE-2024-47846 | Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
33% (1) | CWE-352 | Cross-Site Request Forgery (CSRF) |
33% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
33% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |