MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete permissions to bypass intended suppressrevision and deleterevision restrictions and remove the revision deletion status of arbitrary file revisions by using Special:Undelete.
References
Link | Resource |
---|---|
https://phabricator.wikimedia.org/T132926 | Patch Third Party Advisory |
https://lists.wikimedia.org/pipermail/mediawiki-announce/2016-August/000195.html | Mailing List Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1369613 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-04-20 10:59
Updated : 2017-04-24 13:25
NVD link : CVE-2016-6336
Mitre link : CVE-2016-6336
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
mediawiki
- mediawiki