An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks for certain automatically created MediaWiki user accounts, thus allowing nefarious users to remain unblocked.
References
Link | Resource |
---|---|
https://phabricator.wikimedia.org/T272244 | Third Party Advisory |
https://gerrit.wikimedia.org/r/q/Ie1f4333d5b1c9d17fb2236fe38a31de427a4cc48 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2021-04-22 03:15
Updated : 2022-07-12 17:42
NVD link : CVE-2021-31554
Mitre link : CVE-2021-31554
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE
CWE-863
Incorrect Authorization