Description
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
Remediation
References
Related Vulnerabilities
WordPress Plugin HTML5 Lyrics Karaoke Player Cross-Site Scripting (1.06)
MySQL CVE-2019-2802 Vulnerability (CVE-2019-2802)
MySQL CVE-2024-21142 Vulnerability (CVE-2024-21142)
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-33359)
WordPress Plugin SB Welcome Email Editor Unspecified Vulnerability (4.1)