Access Control Flaw in ReplaceText Extension for MediaWiki
CVE-2021-41801
8.8HIGH
Key Information:
Badges
๐พ Exploit Exists
What is CVE-2021-41801?
The ReplaceText extension in MediaWiki versions up to 1.41 contains an access control vulnerability that allows submitted replace jobs to be executed even after a user is blocked. When a user submits a replace job, and subsequently gets blocked, the job may still be processed later due to a backlog in the job queue. This behavior can lead to unauthorized modifications to content, posing a security risk for MediaWiki installations. Remediation and updates are advised to mitigate this issue.
