CVE-2021-36132
02.07.2021, 13:15
An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform.Enginsight
Vendor | Product | Version |
---|---|---|
mediawiki | mediawiki | 𝑥 ≤ 1.36 |
𝑥
= Vulnerable software versions