Show filters
46 Total Results
Displaying 1-10 of 46
Sort by:
Attacker Value
Unknown
CVE-2022-39193
Disclosure Date: January 20, 2023 (last updated October 08, 2023)
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with suppression rights.
0
Attacker Value
Unknown
CVE-2023-22912
Disclosure Date: January 20, 2023 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated (aka re-used) nonce, allowing an adversary to decrypt.
0
Attacker Value
Unknown
CVE-2023-22910
Disclosure Date: January 20, 2023 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There is XSS in Wikibase date formatting via wikibase-time-precision-* fields. This allows JavaScript execution by staff/admin users who do not intentionally have the editsitejs capability.
0
Attacker Value
Unknown
CVE-2022-47927
Disclosure Date: January 12, 2023 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.
0
Attacker Value
Unknown
CVE-2023-22911
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
0
Attacker Value
Unknown
CVE-2023-22909
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are slow.
0
Attacker Value
Unknown
CVE-2021-44856
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A title blocked by AbuseFilter can be created via Special:ChangeContentModel due to the mishandling of the EditFilterMergedContent hook return value.
0
Attacker Value
Unknown
CVE-2021-44855
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
0
Attacker Value
Unknown
CVE-2021-44854
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis.
0
Attacker Value
Unknown
CVE-2022-34912
Disclosure Date: July 02, 2022 (last updated November 08, 2023)
An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a username contains HTML entities, it won't be escaped.
0