Authentication Bypass Using an Alternate Path or Channel in CreateWiki
Package
CreateWiki
(MediaWiki)
Affected versions
< d0ae79843d689832ccac765d6b1721e668d99ab9
Patched versions
>=d0ae79843d689832ccac765d6b1721e668d99ab9
Impact
Anonymous comments could be made using Special:RequestWikiQueue when sent directly via POST
Patches
Apply d0ae798
References
T9018
For more information
If you have any questions or comments about this advisory: