Rapid7 Vulnerability & Exploit Database

MediaWiki: Missing Authorization (CVE-2020-35625)

Back to Search

MediaWiki: Missing Authorization (CVE-2020-35625)

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
12/21/2020
Created
12/30/2020
Added
12/29/2020
Modified
08/05/2021

Description

An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (defined within PHP or MediaWiki) via a crafted HTML comment, related to a Smarty template. For example, a person in the Widget Editors group could use \MediaWiki\Shell\Shell::command within a comment.

Solution(s)

  • mediawiki-upgrade-latest

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;