Show filters
373 Total Results
Displaying 101-110 of 373
Sort by:
Attacker Value
Unknown
CVE-2021-45472
Disclosure Date: December 24, 2021 (last updated February 23, 2025)
In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.
0
Attacker Value
Unknown
CVE-2021-45471
Disclosure Date: December 24, 2021 (last updated October 07, 2023)
In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.
0
Attacker Value
Unknown
CVE-2021-44858
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
0
Attacker Value
Unknown
CVE-2021-45038
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.
0
Attacker Value
Unknown
CVE-2021-44857
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by action=mcrrestore to replace the content of any arbitrary page (that the user doesn't have edit rights for). This applies to any public wiki, or a private wiki that has at least one page set in $wgWhitelistRead.
0
Attacker Value
Unknown
CVE-2021-41801
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)
0
Attacker Value
Unknown
CVE-2021-41800
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.
0
Attacker Value
Unknown
CVE-2021-41798
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.
0
Attacker Value
Unknown
CVE-2021-41799
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.
0
Attacker Value
Unknown
CVE-2021-42040
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within the Loops extension because egLoopsCountLimit is mishandled. This could lead to memory exhaustion.
0