PT-2021-3351 · Mediawiki+1 · Mediawiki+1

Xzonn

·

Published

2021-04-09

·

Updated

2024-03-06

·

CVE-2021-30155

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.31.12 and earlier MediaWiki versions 1.32.x through 1.35.x before 1.35.2
Description The issue is related to the ContentModelChange function in MediaWiki, which lacks proper authorization. This allows a remote attacker to potentially impact the integrity of protected information by creating and setting the content model of a nonexistent page without correct permissions.
Recommendations For MediaWiki versions 1.31.12 and earlier, update to version 1.31.12 or later. For MediaWiki versions 1.32.x through 1.35.x before 1.35.2, update to version 1.35.2 or later. As a temporary workaround, consider restricting access to the ContentModelChange function to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1712
ALT-PU-2021-2091
BDU:2021-03168
BIT-MEDIAWIKI-2021-30155
CVE-2021-30155
DLA-2648-1
DLA-2648-2
DSA-4889-1
MGASA-2021-0218

Affected Products

Alt Linux
Mediawiki