
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. The vulnerability involves the vector-intro-page MalformedTitleException which is uncaught if it is not a valid title, leading to incorrect web pages (NVD).
The vulnerability exists in the Vector Skin component of MediaWiki, specifically in the VectorComponentUserLinks.php file. When the vector-intro-page message doesn't parse as a valid title, the system fails to catch the MalformedTitleException, resulting in a crash instead of properly handling the error (Wikimedia Gerrit).
When exploited, this vulnerability leads to incorrect web page rendering and potential system crashes, affecting the normal functionality of MediaWiki installations using the Vector Skin component (NVD).
The vulnerability has been patched in MediaWiki versions 1.39.5 and 1.40.1. The fix involves implementing proper exception handling for MalformedTitleException when processing the vector-intro-page message (Wikimedia Gerrit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."