
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform (MediaWiki CVE).
The vulnerability exists in the FileImporter extension's rights validation mechanism. When the $wgFileImporterRequiredRight configuration variable is set to a relaxed state, the system fails to properly validate user permissions before allowing file upload operations (CISA Bulletin). The vulnerability has been assigned a CVSS score of 6.0, indicating a medium severity level.
The vulnerability could allow unauthorized users to upload files to the MediaWiki installation, bypassing intended access controls. This could potentially lead to unauthorized content being added to the wiki, which could include malicious files or inappropriate content (CISA Bulletin).
The vulnerability requires a specific configuration of the FileImporter extension with relaxed settings of the $wgFileImporterRequiredRight variable. An attacker would need to have basic user access to the MediaWiki installation to exploit this vulnerability (MediaWiki CVE).
Administrators should ensure proper configuration of the $wgFileImporterRequiredRight variable and implement strict user permission controls. It is recommended to update to a patched version of the FileImporter extension if available (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."