Vulnerabilities > CVE-2021-31548 - Incorrect Authorization vulnerability in Mediawiki

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
mediawiki
CWE-863

Summary

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. A MediaWiki user who is partially blocked or was unsuccessfully blocked could bypass AbuseFilter and have their edits completed.

Vulnerable Configurations

Part Description Count
Application
Mediawiki
379

Common Weakness Enumeration (CWE)