Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | 1.23.0 (including) | 1.23.16 (including) |
Mediawiki | Mediawiki | 1.27.0 (including) | 1.27.2 (excluding) |
Mediawiki | Mediawiki | 1.28.0 (including) | 1.28.1 (excluding) |
Mediawiki | Ubuntu | artful | * |
Mediawiki | Ubuntu | precise | * |
Mediawiki | Ubuntu | trusty | * |
Mediawiki | Ubuntu | upstream | * |
Mediawiki | Ubuntu | yakkety | * |
Mediawiki | Ubuntu | zesty | * |