CVE-2022-28206: Critical severity mediawiki vulnerability
Published Mar 30, 2022
·Updated
An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles the check for edit rights.
Affected Software
1 affected component
MediaWiki MediaWiki<=1.37.1
Remediation
Event History
Mar 30, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28206?
CVE-2022-28206 is considered a high severity vulnerability due to its impact on edit rights in MediaWiki.
2
How do I fix CVE-2022-28206?
To fix CVE-2022-28206, upgrade to MediaWiki version 1.37.2 or later.
3
What impact does CVE-2022-28206 have on MediaWiki users?
CVE-2022-28206 allows unauthorized users to potentially gain edit rights, leading to unauthorized changes in MediaWiki.
4
Which versions of MediaWiki are affected by CVE-2022-28206?
CVE-2022-28206 affects MediaWiki versions up to and including 1.37.1.
5
Is there a workaround for CVE-2022-28206 until a fix can be applied?
Currently, there is no documented workaround for CVE-2022-28206, so updating to a patched version is recommended.