CVE-2021-30156
- EPSS 0.19%
- Veröffentlicht 09.04.2021 07:15:16
- Zuletzt bearbeitet 21.11.2024 06:03:24
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.
CVE-2021-30159
- EPSS 0.87%
- Veröffentlicht 09.04.2021 07:15:16
- Zuletzt bearbeitet 21.11.2024 06:03:25
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget() uses FOR UPDATE, but it's on...
CVE-2021-30152
- EPSS 0.53%
- Veröffentlicht 09.04.2021 07:15:15
- Zuletzt bearbeitet 21.11.2024 06:03:24
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.
CVE-2021-30154
- EPSS 1.12%
- Veröffentlicht 06.04.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 06:03:24
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS.
CVE-2021-30157
- EPSS 1.01%
- Veröffentlicht 06.04.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 06:03:25
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped,...
CVE-2021-30158
- EPSS 0.61%
- Veröffentlicht 06.04.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 06:03:25
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know...
CVE-2020-29004
- EPSS 0.16%
- Veröffentlicht 29.01.2021 07:15:16
- Zuletzt bearbeitet 21.11.2024 05:23:28
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.
CVE-2020-29005
- EPSS 0.09%
- Veröffentlicht 29.01.2021 07:15:16
- Zuletzt bearbeitet 21.11.2024 05:23:28
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.
CVE-2020-35622
- EPSS 0.17%
- Veröffentlicht 21.12.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:42
An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function was not being properly escaped, allowing for XSS unde...
CVE-2020-35623
- EPSS 0.18%
- Veröffentlicht 21.12.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:43
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able t...