An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks for certain automatically created MediaWiki user accounts, thus allowing nefarious users to remain unblocked.
References
Link | Resource |
---|---|
https://phabricator.wikimedia.org/T272244 | Third Party Advisory |
https://gerrit.wikimedia.org/r/q/Ie1f4333d5b1c9d17fb2236fe38a31de427a4cc48 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2021-04-21 20:15
Updated : 2022-07-12 10:42
NVD link : CVE-2021-31554
Mitre link : CVE-2021-31554
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
mediawiki
- mediawiki