Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator. (CVE-2023-3550) An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers. (CVE-2023-45360) An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediate revisions by the same user not shown") ignores username suppression. This is an information leak. (CVE-2023-45362) An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x b...
- https://bugs.mageia.org/show_bug.cgi?id=33156
- https://www.cve.org/CVERecord?id=CVE-2023-3550
- https://www.cve.org/CVERecord?id=CVE-2023-45359
- https://www.cve.org/CVERecord?id=CVE-2023-45360
- https://www.cve.org/CVERecord?id=CVE-2023-45361
- https://www.cve.org/CVERecord?id=CVE-2023-45362
- https://www.cve.org/CVERecord?id=CVE-2023-45363
- https://www.cve.org/CVERecord?id=CVE-2023-45364
- https://www.cve.org/CVERecord?id=CVE-2023-51704
- 9/core/mediawiki-1.35.14-1.mga9
Get the latest Linux and open source security news straight to your inbox.