NA

CVE-2024-34502

Published: 05/05/2024 Updated: 06/05/2024

Vulnerability Summary

An issue exists in WikibaseLexeme in MediaWiki prior to 1.39.6, 1.40.x prior to 1.40.2, and 1.41.x prior to 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.