CVE-2022-28201 Information

Share on:

Description

An issue was discovered in MediaWiki before 1.35.6 1.36.x before 1.36.4 and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion because a bare local interwiki is mishandled for the mainpage message.

Reference

https://phabricator.wikimedia.org/T297571 https://blog.legoktm.com/2022/07/03/a-belated-writeup-of-cve-2022-28201-in-mediawiki.html