Security Advisory

CVE-2019-19709

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-12-11 01:33:11
Last updated 2024-08-05 02:25:12
Assigner mitre
State PUBLISHED

Description

MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.