CVE-2023-36674

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/08/2023
Last modified:
08/10/2024

Description

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.35.11 (excluding)
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.36.0 (including) 1.38.7 (excluding)
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.39.0 (including) 1.39.4 (excluding)
cpe:2.3:a:mediawiki:mediawiki:1.40.0:*:*:*:*:*:*:*