MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not throttle file uploads, which allows remote authenticated users to have unspecified impact via multiple file uploads.
2015-11-09T18:59:02.727
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:C
8.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mediawiki | mediawiki | ≤ 1.23.10 | Yes |
Application | mediawiki | mediawiki | 1.24.0 | Yes |
Application | mediawiki | mediawiki | 1.24.1 | Yes |
Application | mediawiki | mediawiki | 1.24.2 | Yes |
Application | mediawiki | mediawiki | 1.24.3 | Yes |
Application | mediawiki | mediawiki | 1.25.0 | Yes |
Application | mediawiki | mediawiki | 1.25.1 | Yes |
Application | mediawiki | mediawiki | 1.25.2 | Yes |