An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 08:10
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/ - | |
| References | () https://phabricator.wikimedia.org/T335612 - Issue Tracking, Patch | 
08 Oct 2024, 15:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-20 | 
07 Nov 2023, 04:16
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
 | 
15 Sep 2023, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
02 Sep 2023, 03:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
25 Aug 2023, 14:08
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Mediawiki Mediawiki mediawiki | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 5.3 | 
| References | (MISC) https://phabricator.wikimedia.org/T335612 - Issue Tracking, Patch | |
| CPE | cpe:2.3:a:mediawiki:mediawiki:1.40.0:*:*:*:*:*:*:* cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo | 
20 Aug 2023, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-08-20 18:15
Updated : 2024-11-21 08:10
NVD link : CVE-2023-36674
Mitre link : CVE-2023-36674
CVE.ORG link : CVE-2023-36674
JSON object : View
Products Affected
                mediawiki
- mediawiki
CWE
                