PT-2021-21123 · Mediawiki+1 · Mediawiki+1

Dannys712

·

Published

2021-06-12

·

Updated

2024-03-06

·

CVE-2021-36126

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MediaWiki versions prior to 1.37
Description: An issue was discovered in the AbuseFilter extension. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be invalid on a wiki. This would result in a fatal error, and potentially fail to block or restrict a potentially nefarious user.
Recommendations: For MediaWiki versions prior to 1.37, update to a version that includes the fix for this issue to prevent potential fatal errors and ensure proper blocking or restriction of potentially nefarious users.

Exploit

Fix

Related Identifiers

ALT-PU-2021-1991
ALT-PU-2021-2091
BIT-MEDIAWIKI-2021-36126
CVE-2021-36126

Affected Products

Alt Linux
Mediawiki