An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.
References
Configurations
Configuration 1 (hide)
|
History
07 Nov 2023, 04:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
25 Aug 2023, 14:08
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:mediawiki:mediawiki:1.40.0:*:*:*:*:*:*:* cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
References | (MISC) https://phabricator.wikimedia.org/T335612 - Issue Tracking, Patch | |
First Time |
Mediawiki
Mediawiki mediawiki |
20 Aug 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-20 18:15
Updated : 2024-10-08 15:35
NVD link : CVE-2023-36674
Mitre link : CVE-2023-36674
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE