PT-2019-5230 · Mediawiki+1 · Mediawiki+1
Bugreporter
·
Publicado
2019-12-10
·
Atualizado
2023-02-01
·
CVE-2019-19709
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki versions prior to 1.33.1
Description
The issue allows attackers to bypass the Title blacklist protection mechanism. This can be achieved by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using
redirect=1 in the "action API" when editing that page. The vulnerability is related to redirecting URLs to untrusted sites, which can allow a remote attacker to gain unauthorized access to confidential data and impact data integrity.Recommendations
For MediaWiki versions prior to 1.33.1, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting the use of the
redirect=1 parameter in the action API until a patch is available.Exploit
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Mediawiki