8.8
CVSSv3

CVE-2021-41801

Published: 11/10/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The ReplaceText extension up to and including 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki

Vendor Advisories

Multiple security issues were found in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting, denial of service and a bypass of restrictions in the Replace Text extension For the oldstable distribution (buster), these problems have been fixed in version 1:13116-1~deb10u1 For the stable distribution (bull ...
A security issue has been found in MediaWiki before version 1362 ReplaceText continues performing actions if the user no longer has the correct permission (such as by being blocked) ...