An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/ - | |
References | () https://phabricator.wikimedia.org/T335612 - Issue Tracking, Patch |
08 Oct 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 |
07 Nov 2023, 04:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
15 Sep 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 Sep 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
25 Aug 2023, 14:08
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://phabricator.wikimedia.org/T335612 - Issue Tracking, Patch | |
First Time |
Mediawiki mediawiki
Mediawiki |
|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* cpe:2.3:a:mediawiki:mediawiki:1.40.0:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
21 Aug 2023, 12:47
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-20 18:15
Updated : 2024-11-21 08:10
NVD link : CVE-2023-36674
Mitre link : CVE-2023-36674
CVE.ORG link : CVE-2023-36674
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE