Mediawiki

Mediawiki

419 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.21%
  • Veröffentlicht 10.01.2022 14:11:28
  • Zuletzt bearbeitet 21.11.2024 06:33:41

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service (resource consumption) can be accomplished by searching for a very long key in a Language Name Search.

  • EPSS 0.57%
  • Veröffentlicht 10.01.2022 14:11:27
  • Zuletzt bearbeitet 21.11.2024 06:33:41

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.

  • EPSS 0.53%
  • Veröffentlicht 10.01.2022 14:11:27
  • Zuletzt bearbeitet 21.11.2024 06:33:41

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.

  • EPSS 1.24%
  • Veröffentlicht 24.12.2021 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:32:16

In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.

  • EPSS 0.97%
  • Veröffentlicht 24.12.2021 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:32:16

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

Exploit
  • EPSS 1.25%
  • Veröffentlicht 24.12.2021 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:32:17

In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).

  • EPSS 0.97%
  • Veröffentlicht 24.12.2021 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:32:17

In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.

  • EPSS 1.33%
  • Veröffentlicht 20.12.2021 09:15:06
  • Zuletzt bearbeitet 21.11.2024 06:31:37

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one...

  • EPSS 0.87%
  • Veröffentlicht 17.12.2021 04:15:39
  • Zuletzt bearbeitet 21.11.2024 06:31:37

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by action=mcrrestore to replace the content of any arbitrary page (that the user doesn't have edit right...

  • EPSS 1.35%
  • Veröffentlicht 17.12.2021 04:15:39
  • Zuletzt bearbeitet 21.11.2024 06:31:50

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.