Description
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy WP SMTP Security Bypass (1.4.2)
WordPress Plugin Waitlist Woocommerce (Back in stock notifier) Cross-Site Request Forgery (2.5.1)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5487)
Zenphoto Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5595)