ZeroHour

CVE-2021-30158

PoC
CVSS 3.1
5.3 medium
EPSS
2%p76
Published
()
Modified
Description

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.

Vendors
mediawikidebianfedoraproject
Products
mediawiki, debian linux, fedora
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.