Exposure of Resource to Wrong Sphere in MediaWiki - CVE-2021-31552
Published: April 26, 2021
MediaWiki
MediaWiki.org
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected software incorrectly executes certain rules related to blocking accounts after account creation in the AbuseFilter extension. A remote authenticated attacker can create user accounts or enumerate any number of IP addresses related to these account creations.