CVE Vulnerabilities

CVE-2023-36674

Published: Aug 20, 2023 | Modified: Nov 07, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.35.11 (excluding)
Mediawiki Mediawiki 1.36.0 (including) 1.38.7 (excluding)
Mediawiki Mediawiki 1.39.0 (including) 1.39.4 (excluding)
Mediawiki Mediawiki 1.40.0 (including) 1.40.0 (including)

References