Show filters
373 Total Results
Displaying 121-130 of 373
Sort by:
Attacker Value
Unknown
CVE-2021-36125
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).
0
Attacker Value
Unknown
CVE-2021-36128
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented.
0
Attacker Value
Unknown
CVE-2021-36129
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does not validate the parameter for aggregategroup when action=remove is set, thus allowing users with the translate-manage right to silently delete various groups' metadata.
0
Attacker Value
Unknown
CVE-2021-36131
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a privileged user could inject arbitrary HTML and JavaScript within various data fields. The attack could easily propagate across many pages for many users.
0
Attacker Value
Unknown
CVE-2021-31555
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. It did not validate the oarc_version (aka oauth_registered_consumer.oarc_version) parameter's length.
0
Attacker Value
Unknown
CVE-2021-31552
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while blocking only the IP address used to create an account (and not the user account itself). Such rules could also be used by a nefarious, unprivileged user to catalog and enumerate any number of IP addresses related to these account creations.
0
Attacker Value
Unknown
CVE-2021-31548
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. A MediaWiki user who is partially blocked or was unsuccessfully blocked could bypass AbuseFilter and have their edits completed.
0
Attacker Value
Unknown
CVE-2021-31547
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. Its AbuseFilterCheckMatch API reveals suppressed edits and usernames to unprivileged users through the iteration of crafted AbuseFilter rules.
0
Attacker Value
Unknown
CVE-2021-31553
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing whitespace could be stored in the cu_log database table such that denial of service occurred for certain CheckUser extension pages and functionality. For example, the attacker could turn off Special:CheckUserLog and thus interfere with usage tracking.
0
Attacker Value
Unknown
CVE-2021-31549
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The Special:AbuseFilter/examine form allowed for the disclosure of suppressed MediaWiki usernames to unprivileged users.
0