Related Vulnerabilities: CVE-2021-35197  

A security issue has been found in MediaWiki before version 1.36.1 that allows blocked users to purge pages.

Severity Medium

Remote Yes

Type Access restriction bypass

Description

A security issue has been found in MediaWiki before version 1.36.1 that allows blocked users to purge pages.

AVG-2093 mediawiki 1.36.0-1 Medium Vulnerable

https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/YR3X4L2CPSEJVSY543AWEO65TD6APXHP/
https://phabricator.wikimedia.org/T280226
https://releases.wikimedia.org/mediawiki/1.36/mediawiki-1.36.1.patch.gz