Description
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
Remediation
References
Related Vulnerabilities
MediaWiki Unquoted Search Path or Element Vulnerability (CVE-2021-31553)
PHP Other Vulnerability (CVE-2007-1475)
phpBB CVE-2008-3224 Vulnerability (CVE-2008-3224)
WordPress Plugin WordPress Colorbox Lightbox Cross-Site Scripting (1.1.2)
WordPress Plugin Gallery-Responsive Photo and Video Gallery by Limb Cross-Site Scripting (1.3.2)