CVE-2021-36132: High severity mediawiki vulnerability
An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36132?
CVE-2021-36132 is classified as a medium severity vulnerability.
How do I fix CVE-2021-36132?
To fix CVE-2021-36132, upgrade MediaWiki to version 1.37 or later.
What does CVE-2021-36132 affect in MediaWiki?
CVE-2021-36132 affects the FileImporter extension in MediaWiki up to version 1.36.
Who can exploit CVE-2021-36132?
CVE-2021-36132 can be exploited by users with insufficient rights due to relaxed configurations.
What operations can be performed due to CVE-2021-36132?
CVE-2021-36132 allows unauthorized users to perform file importing operations in MediaWiki.