Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-36674


An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.


Published

2023-08-20T18:15:09.930

Last Modified

2024-11-21T08:10:19.077

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mediawiki mediawiki < 1.35.11 Yes
Application mediawiki mediawiki < 1.38.7 Yes
Application mediawiki mediawiki < 1.39.4 Yes
Application mediawiki mediawiki 1.40.0 Yes

References