PT-2022-19691 · Mediawiki · Mediawiki Createredirect Extension
Rhinosf1
·
Published
2022-04-21
·
Updated
2022-05-02
·
CVE-2022-29547
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki CreateRedirect extension versions prior to 2022-04-14
Description
The issue concerns the CreateRedirect extension for MediaWiki, where it fails to properly check user permissions for editing the target page. This could allow unauthorized or blocked users to edit pages they should not have access to.
Recommendations
For MediaWiki CreateRedirect extension versions prior to 2022-04-14, update to a version released after 2022-04-14 to resolve the issue. As a temporary workaround, consider restricting access to the extension's functionality to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mediawiki Createredirect Extension