Security Advisory

CVE-2021-30152

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-04-09 06:08:35
Last updated 2024-08-03 22:24:59
Assigner mitre
State PUBLISHED

Description

An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.