Improper access control in MediaWiki - CVE-2019-12472
Published: July 10, 2019 / Updated: July 17, 2020
MediaWiki
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.