CVE-2023-36674
20.08.2023, 18:15
An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mediawiki | mediawiki | 𝑥 < 1.35.11 |
| mediawiki | mediawiki | 1.36.0 ≤ 𝑥 < 1.38.7 |
| mediawiki | mediawiki | 1.39.0 ≤ 𝑥 < 1.39.4 |
| mediawiki | mediawiki | 1.40.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References