Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-29897

Опубликовано: 28 мар. 2024
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or (suppressrevision) on any wiki in the farm to access suppressed wiki requests by going to the request's entry on Special:RequestWikiQueue on the wiki where they have these rights. The same vulnerability was present briefly on the REST API before being quickly corrected in commit 6bc0685. To our knowledge, the vulnerable commits of the REST API are not running in production anywhere. This vulnerability is fixed in 23415c17ffb4832667c06abcf1eadadefd4c8937.

EPSS

Процентиль: 19%
0.00061
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-200

EPSS

Процентиль: 19%
0.00061
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-200