CVE-2021-44858 Information
Share on:
Jun 06, 2022
cve
Description
An issue was discovered in MediaWiki before 1.35.5 1.36.x before 1.36.3 and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://www.mediawiki.org/wiki/2021-12_security_release/FAQ https://phabricator.wikimedia.org/T297322
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5