← voltar
CVE-2021-29483criticalCWE-200

wikiconfig API leaked private config variables set through ManageWiki

28Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 9.4epss 1.2%
probabilidade de exploração
1.2%top 34% das CVEs
exploração observada
nãonenhuma fonte reporta
ManageWiki is an extension to the MediaWiki project. The 'wikiconfig' API leaked the value of private configuration variables set through the ManageWiki variable to all users. This has been patched by https://github.com/miraheze/ManageWiki/compare/99f3b2c8af18...befb83c66f5b.patch. If you are unable to patch set `$wgAPIListModules['wikiconfig'] = 'ApiQueryDisabled';` or remove private config as a workaround.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Produtos afetados
miraheze · ManageWiki