PT-2021-3348 · Mediawiki+1 · Mediawiki+1
Magiczocker10
·
Published
2021-04-09
·
Updated
2024-03-06
·
CVE-2021-30152
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki versions 1.31.13 and earlier
MediaWiki versions 1.32.x through 1.35.1
Description
An issue was discovered in MediaWiki related to the "protect" page function via the MediaWiki API. This issue allows a user to protect a page to a higher level than their current permissions. The problem is associated with inadequate access control, which could allow a remote attacker to impact the integrity of protected information.
Recommendations
For MediaWiki versions 1.31.13 and earlier, update to version 1.31.13 or later.
For MediaWiki versions 1.32.x through 1.35.1, update to version 1.35.2 or later.
As a temporary workaround, consider restricting access to the MediaWiki API "protect" page function until a patch is available.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Mediawiki