An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.
References
| Link | Resource |
|---|---|
| https://phabricator.wikimedia.org/T335612 | Issue Tracking Patch |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-08-20 18:15
Updated : 2023-08-25 14:08
NVD link : CVE-2023-36674
Mitre link : CVE-2023-36674
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE
