vulnerability

FreeBSD: VID-f84ab297-2285-11ec-9e79-08002789875b (CVE-2021-41801): mediawiki -- multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Oct 1, 2021
Added
Nov 4, 2022
Modified
Mar 25, 2026

Description

Mediawiki reports: (T285515, CVE-2021-41798) SECURITY: XSS vulnerability in Special:Search. (T290379, CVE-2021-41799) SECURITY: ApiQueryBacklinks can cause a full table scan. (T284419, CVE-2021-41800) SECURITY: fix PoolCounter protection of Special:Contributions. (T279090, CVE-2021-41801) SECURITY: ReplaceText continues performing actions if the user no longer has the correct permission (such as by being blocked).

Solutions

freebsd-upgrade-package-mediawiki131freebsd-upgrade-package-mediawiki135freebsd-upgrade-package-mediawiki136
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.