CVE-2021-45038 Information
Jun 07, 2022
cve
Description
An issue was discovered in MediaWiki before 1.35.5 1.36.x before 1.36.3 and 1.37.x before 1.37.1. By using an action=rollback query attackers can view private wiki contents.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://www.mediawiki.org/wiki/2021-12_security_release/FAQ https://phabricator.wikimedia.org/T297574
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: