7.5
CVSSv3

CVE-2021-35197

Published: 02/07/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

In MediaWiki prior to 1.31.15, 1.32.x up to and including 1.35.x prior to 1.35.3, and 1.36.x prior to 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Multiple security issues were found in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting, denial of service and a bypass of restrictions in the Replace Text extension For the oldstable distribution (buster), these problems have been fixed in version 1:13116-1~deb10u1 For the stable distribution (bull ...
In MediaWiki before 13115, 132x through 135x before 1353, and 136x before 1361, bots have certain unintended API access When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented) ...
A security issue has been found in MediaWiki before version 1361 that allows blocked users to purge pages ...