Permissions, Privileges, and Access Controls in MediaWiki - CVE-2019-19709
Published: December 28, 2019
MediaWiki
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.