File Importer Extension Rights Misconfiguration in MediaWiki by Wikimedia
CVE-2022-28206

9.8CRITICAL

Key Information:

Vendor

Mediawiki

Status
Vendor
CVE Published:
30 March 2022

What is CVE-2022-28206?

A vulnerability was identified in the MediaWiki platform, specifically within the FileImporter extension. The flaw arises in the ImportPlanValidator.php script, which improperly handles checks for edit rights. This misconfiguration could potentially allow unauthorized users to gain edit access, posing risks to the integrity of the content managed within the MediaWiki environment. Institutions using affected versions, particularly up to 1.37.1, should take precautionary measures to mitigate this risk.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.