Wikimedia · Mediawiki · CVE-2013-2114
**Name of the Vulnerable Software and Affected Versions**
MediaWiki versions 1.19 through 1.19.6
MediaWiki versions 1.20.x before 1.20.6
**Description**
The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension, due to an unrestricted file upload vulnerability in the chunk upload API.
**Recommendations**
For MediaWiki versions 1.19 through 1.19.6, update to version 1.19.7 or later.
For MediaWiki versions 1.20.x before 1.20.6, update to version 1.20.6 or later.
As a temporary workaround, consider restricting access to the chunk upload API until a patch is available.