PT-2023-6729 · Mediawiki+2 · Mediawiki+2
Carlos Bello
·
Publicado
2023-09-25
·
Atualizado
2025-08-14
·
CVE-2023-3550
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MediaWiki version 1.40.0
Description
The issue exists due to the lack of protection for the web page structure. A remote attacker with a low-privileged user account can exploit this by sending a malicious link to the instance administrator, allowing them to become an administrator if the instance administrator allows XML file uploads. This can lead to a security breach.
Recommendations
For MediaWiki version 1.40.0, restrict access to XML file uploads to prevent exploitation until a patch is available. As a temporary workaround, consider disabling XML file uploads to minimize the risk of exploitation.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Mediawiki
Red Os