PT-2021-18245 · Miraheze · Managewiki
Universal-Omega
·
Published
2021-04-28
·
Updated
2021-05-08
·
CVE-2021-29483
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H |
Name of the Vulnerable Software and Affected Versions:
ManageWiki (affected versions not specified)
Description:
The issue concerns the ManageWiki extension to the MediaWiki project, where the 'wikiconfig' API endpoint leaked private configuration variables set through the ManageWiki variable to all users.
Recommendations:
For all affected versions, consider setting
$wgAPIListModules['wikiconfig'] = 'ApiQueryDisabled'; or remove private config as a workaround until a patch is applied.
Apply the patch available at https://github.com/miraheze/ManageWiki/compare/99f3b2c8af18...befb83c66f5b.patch to resolve the issue.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Managewiki