SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-36129

The Aggregategroups Action API module does not validate the parameter for aggregategroup when action=remove is set, thus allowing users with the translate-manage right to silently delete various groups' metadata.

MEDIUM 4.3EPSS 0.60%

Does this matter?

Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does not validate the parameter for aggregategroup when action=remove is set, thus allowing users with the translate-manage right to silently delete various groups' metadata.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.60% probability · 47th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
mediawiki/mediawiki
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.