Description
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Waitlist Woocommerce (Back in stock notifier) Cross-Site Request Forgery (2.5.1)
MySQL CVE-2021-35647 Vulnerability (CVE-2021-35647)
WordPress Plugin Chamber Dashboard Business Directory Cross-Site Scripting (3.2.8)
WebLogic CVE-2019-2395 Vulnerability (CVE-2019-2395)
WordPress Plugin LearnPress-WordPress LMS Multiple Vulnerabilities (4.1.7.3.2)