CVE Vulnerabilities

CVE-2023-36674

Published: Aug 20, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.

Affected Software

NameVendorStart VersionEnd Version
MediawikiMediawiki*1.35.11 (excluding)
MediawikiMediawiki1.36.0 (including)1.38.7 (excluding)
MediawikiMediawiki1.39.0 (including)1.39.4 (excluding)
MediawikiMediawiki1.40.0 (including)1.40.0 (including)
MediawikiUbuntubionic*
MediawikiUbuntufocal*
MediawikiUbuntukinetic*
MediawikiUbuntulunar*
MediawikiUbuntutrusty*
MediawikiUbuntuupstream*
MediawikiUbuntuxenial*

References