Mediawiki

Mediawiki

395 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 06.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:07

An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within the Loops extension because egLoopsCountLimit is mishandled. This could lead to memory exhaustion.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 06.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:07

An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript via the setchange log.

  • EPSS 0.4%
  • Veröffentlicht 06.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:07

An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The growthexperiments-edit-config-error-invalid-title MediaWiki message was not being properly sanitized and allowed for the injection ...

  • EPSS 0.44%
  • Veröffentlicht 06.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:07

An issue was discovered in Special:MediaSearch in the MediaSearch extension in MediaWiki through 1.36.2. The suggestion text (a parameter to mediasearch-did-you-mean) was not being properly sanitized and allowed for the injection and execution of HTM...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 06.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:07

An issue was discovered in the Mentor dashboard in the GrowthExperiments extension in MediaWiki through 1.36.2. The Growthexperiments-mentor-dashboard-mentee-overview-add-filter-total-edits-headline, growthexperiments-mentor-dashboard-mentee-overview...

  • EPSS 0.66%
  • Veröffentlicht 12.08.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:05:54

An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.

Exploit
  • EPSS 0.73%
  • Veröffentlicht 02.07.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:01

In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 02.07.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:13:09

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configura...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 02.07.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:13:10

An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could als...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 02.07.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:13:10

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which, for a suppressed MediaWiki user, were different than for any other user, thus easily disclosing suppresse...