Description
MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.
Remediation
References
Related Vulnerabilities
PostgreSQL Resource Management Errors Vulnerability (CVE-2009-0922)
WordPress Other Vulnerability (CVE-2006-0733)
WordPress Plugin The Plus Addons for Elementor Cross-Site Scripting (4.1.11)
XWiki Incorrect Authorization Vulnerability (CVE-2023-32069)
Oracle Database Server CVE-2009-0997 Vulnerability (CVE-2009-0997)