Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-34506


An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service.


Published

2024-05-05T19:15:07.253

Last Modified

2025-06-17T16:40:07.530

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mediawiki mediawiki < 1.39.7 Yes
Application mediawiki mediawiki < 1.40.3 Yes
Application mediawiki mediawiki < 1.41.1 Yes
Operating System fedoraproject fedora 40 Yes

References