Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rq44-cfp6-2c3c

Опубликовано: 05 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.

EPSS

Процентиль: 37%
0.00159
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-352

Связанные уязвимости

redhat
больше 1 года назад

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.

CVSS3: 9.8
nvd
больше 1 года назад

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.

CVSS3: 5.4
fstec
почти 2 года назад

Уязвимость расширения WikibaseLexeme программного средства для реализации гипертекстовой среды MediaWiki, позволяющая нарушителю повысить свои привилегии

CVSS3: 5.4
redos
больше 1 года назад

Множественные уязвимости mediawiki

EPSS

Процентиль: 37%
0.00159
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-352