GHSA-pjv5-vv93-p648
Dashboard / Vulnerabilities / GHSA-pjv5-vv93-p648
Summary: Possible to circumvent title-blacklist
Details: MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-19709, https://gerrit.wikimedia.org/r/q/Ie54f366986056c876eade0fcad6c41f70b8b8de8, https://github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2019-19709.yaml, https://github.com/wikimedia/mediawiki, https://phabricator.wikimedia.org/T239466, https://seclists.org/bugtraq/2019/Dec/48, https://www.debian.org/security/2019/dsa-4592
Affected packages
Package
Name: mediawiki/core
Purl: pkg:composer/mediawiki/core
Affected ranges
Type: ECOSYSTEM
Events:
