CVE-2020-26121
An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a mishandled distinction between an upload restriction and a create restriction. An attacker cannot leverage this to overwrite anything, but can leverage this to force a wiki to have a page with a disallowed title.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.28% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- mediawiki/mediawiki · fedoraproject/fedora
- Source
- cve@mitre.org
References
- https://commons.wikimedia.org/w/index.php?oldid=454609892#File:Wiki.pngVendor Advisory
- https://gerrit.wikimedia.org/r/q/Ib852a96afc4dca10516d0510e69c10f9892b351bPatch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6/
- https://phabricator.wikimedia.org/T262628Issue Tracking, Patch, Vendor Advisory
- https://commons.wikimedia.org/w/index.php?oldid=454609892#File:Wiki.pngVendor Advisory
- https://gerrit.wikimedia.org/r/q/Ib852a96afc4dca10516d0510e69c10f9892b351bPatch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6/
- https://phabricator.wikimedia.org/T262628Issue Tracking, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.