PT-2024-32888 · Mediawiki+2 · Mediawiki Abusefilter Extension+2
Dom_Walden
·
Published
2024-10-04
·
Updated
2025-10-06
·
CVE-2024-47913
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki AbuseFilter extension versions prior to 1.39.9
MediaWiki AbuseFilter extension versions 1.40.x
MediaWiki AbuseFilter extension versions 1.41.x prior to 1.41.3
MediaWiki AbuseFilter extension versions 1.42.x prior to 1.42.2
Description
An issue was discovered in the AbuseFilter extension for MediaWiki. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.
Recommendations
For versions prior to 1.39.9, update to version 1.39.9 or later.
For versions 1.40.x, update to version 1.41.3 or later.
For versions 1.41.x prior to 1.41.3, update to version 1.41.3 or later.
For versions 1.42.x prior to 1.42.2, update to version 1.42.2 or later.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Mediawiki Abusefilter Extension
Red Os