Total vulnerabilities in the database
The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)
Software | From | Fixed in |
---|---|---|
mediawiki / mediawiki | 1.36.0 | 1.36.2 |
mediawiki / mediawiki | 1.35.0 | 1.35.4 |
mediawiki / mediawiki | - | 1.31.16 |