An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | * | 1.35.5 (excluding) |
Mediawiki | Mediawiki | 1.36.0 (including) | 1.36.3 (excluding) |
Mediawiki | Mediawiki | 1.37.0 (including) | 1.37.1 (excluding) |
Mediawiki | Ubuntu | bionic | * |
Mediawiki | Ubuntu | esm-apps/bionic | * |
Mediawiki | Ubuntu | esm-apps/focal | * |
Mediawiki | Ubuntu | focal | * |
Mediawiki | Ubuntu | hirsute | * |
Mediawiki | Ubuntu | impish | * |
Mediawiki | Ubuntu | trusty | * |
Mediawiki | Ubuntu | upstream | * |