Permissions, Privileges, and Access Controls in MediaWiki - CVE-2019-19709
Published: December 28, 2019
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
Affected software
mediawiki (Debian package)
How to mitigate CVE-2019-19709
mediawiki (Debian package) - addressed in versions 1:1.27.7-1~deb9u3, 1:1.31.6-1~deb10u1