First published: Fri Jun 30 2023(Updated: )
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to block a user fails after a temporary browser hang and a DBQueryDisconnectedError error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <=1.39.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37303 is an issue discovered in the CheckUser extension for MediaWiki through version 1.39.3.
The severity of CVE-2023-37303 is critical with a severity value of 9.8.
CVE-2023-37303 affects MediaWiki through version 1.39.3.
To fix CVE-2023-37303, you should update the CheckUser extension for MediaWiki to a version that is not affected.
You can find more information about CVE-2023-37303 in the provided references: [Reference 1](https://gerrit.wikimedia.org/r/q/I10a9273c542576b3f7bb38de68dcd2aa41cfb1b0), [Reference 2](https://phabricator.wikimedia.org/T338276).