Description
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google Doc Embedder SQL Injection (2.5.16)
MyBB Improper Access Control Vulnerability (CVE-2016-9412)
WordPress Plugin MainWP Dashboard Cross-Site Scripting (3.1.2)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2023-0217)
WordPress Plugin LB Tube Video for WordPress Cross-Site Scripting (1.0)