PT-2018-3640 · Wikimedia+1 · Mediawiki+1

Az1568

·

Published

2018-10-01

·

Updated

2024-03-06

·

CVE-2020-35477

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.1
Description The issue is related to a lack of input validation mechanism in MediaWiki, which can be exploited by a remote attacker to impact data integrity. Specifically, when MediaWiki:Mainpage is set to Special:MyLanguage/Main Page, visiting a log entry on Special:Log and toggling the "Change visibility of selected log entries" checkbox (or a tags checkbox) next to it results in a redirection to the main page's action=historysubmit, instead of displaying a revision-deletion form as expected.
Recommendations For MediaWiki versions prior to 1.35.1, update to version 1.35.1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the "Change visibility of selected log entries" checkbox (or tags checkbox) on Special:Log pages until the update is applied.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3554
ALT-PU-2020-3568
BDU:2021-01771
BIT-MEDIAWIKI-2020-35477
CVE-2020-35477
DLA-2504-1
DSA-4816-1
MGASA-2021-0086

Affected Products

Alt Linux
Mediawiki