An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.
References
Configurations
Configuration 1 (hide)
|
History
08 Oct 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 |
20 Aug 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-20 18:15
Updated : 2024-10-08 15:35
NVD link : CVE-2023-36674
Mitre link : CVE-2023-36674
CVE.ORG link : CVE-2023-36674
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE