PatchSiren cyber security CVE debrief
CVE-2024-23176 MediaWiki CVE debrief
A cross-site scripting (XSS) vulnerability was discovered in the MassMessage extension for MediaWiki before version 1.40.2. This issue allows an attacker to inject malicious scripts into the 'Special:MassMessage?uselang=x-xss' URL, potentially leading to security risks. The vulnerability arises from inadequate input validation and sanitization in the extension, which enables attackers to execute arbitrary scripts in the context of affected user browsers. Defenders should assess exposure and prioritize patching or mitigating the vulnerability to prevent potential security breaches.
- Vendor
- MediaWiki
- Product
- MassMessage extension
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-14
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-14
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for MediaWiki installations with the MassMessage extension should assess exposure and prioritize patching or mitigating the vulnerability.
Why it matters
CVE-2024-23176 is a medium-severity XSS vulnerability in the MassMessage extension for MediaWiki before 1.40.2. Defenders should verify versions, assess exposure, and apply patches to prevent potential script injection attacks.
- Potential for attacker-controlled script execution in user browsers
- Risk of defacement or unauthorized content injection
- Possible theft of user sessions or sensitive information
- Need for verification of MediaWiki and MassMessage extension versions
Technical summary
The MassMessage extension in MediaWiki before 1.40.2 is vulnerable to cross-site scripting (XSS) attacks due to improper handling of the 'uselang' parameter in the 'Special:MassMessage' URL. Specifically, the i18n key 'massmessage-form-page-help' allows XSS, enabling attackers to inject malicious scripts. This issue stems from insufficient input validation and sanitization, highlighting the need for defenders to verify MediaWiki and MassMessage extension versions, assess exposure, and apply patches or workarounds as recommended by the vendor.
Defensive priority
Defenders should prioritize verifying the version of MediaWiki and the MassMessage extension in use, assessing exposure to the vulnerable component, and applying patches or workarounds as recommended by the vendor.
Recommended defensive actions
- Verify the version of MediaWiki and the MassMessage extension in use
- Assess exposure to the vulnerable component
- Apply patches or workarounds as recommended by the vendor
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, including its CVSS score and vector. However, the corpus does not establish versions, exploitation, impact, or remediation beyond vendor recommendations.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-23176 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-23176
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-23176 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-23176
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.wikimedia.org/hyperkitty/list/[email protected]/message/TDBUBCCOQJUT4SCHJNPHKQNPBUUETY52/
-
Source reference
Unverified legacy reference
URL: https://phabricator.wikimedia.org/T347742
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.