Description
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.
Remediation
References
Related Vulnerabilities
Jboss EAP Improper Neutralization of CRLF Sequences ('CRLF Injection') Vulnerability (CVE-2016-4993)
WordPress Plugin Appointments Cross-Site Scripting (2.2.2.2)
Joomla! Core 1.0.x Multiple Unspecified Vulnerabilities (1.0.0 - 1.0.10)
WordPress Plugin iPages Flipbook For WordPress Cross-Site Scripting (1.4.2)
silverstripeCMS Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-25817)