PT-2022-18875 · Mediawiki+1 · Mediawiki+2

Dylsss

·

Published

2022-03-30

·

Updated

2024-03-06

·

CVE-2022-28206

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MediaWiki versions through 1.37.1
Description An issue was discovered in the ImportPlanValidator.php file of the FileImporter extension, where it mishandles the check for edit rights.
Recommendations For MediaWiki versions through 1.37.1, consider disabling the FileImporter extension until a patch is available. Restrict access to the ImportPlanValidator.php file to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

ALT-PU-2022-2140
ALT-PU-2022-2428
BIT-MEDIAWIKI-2022-28206
CVE-2022-28206

Affected Products

Alt Linux
Fileimporter Extension
Mediawiki