PT-2020-16300 · Wikimedia+1 · Mediawiki+2

Cptviraj

·

Published

2020-09-27

·

Updated

2024-03-06

·

CVE-2020-26121

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.34.4 FileImporter extension for MediaWiki versions prior to 1.34.4
Description An issue in the FileImporter extension allows an attacker to import a file into a protected page, bypassing "page creation" restrictions. This occurs due to a mishandled distinction between upload and create restrictions. The attacker cannot overwrite existing content but can force a wiki to have a page with a disallowed title.
Recommendations For MediaWiki versions prior to 1.34.4, update to version 1.34.4 or later to resolve the issue. For the FileImporter extension, update to a version compatible with MediaWiki 1.34.4 or later to fix the problem.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3022
ALT-PU-2020-3055
BIT-MEDIAWIKI-2020-26121
CVE-2020-26121

Affected Products

Alt Linux
Fileimporter Extension
Mediawiki