An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing whitespace could be…
mitre·CWE-428·Published 2021-04-22
An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing whitespace could be stored in the cu_log database table such that denial of service occurred for certain CheckUser extension pages and functionality. For example, the attacker could turn off Special:CheckUserLog and thus interfere with usage tracking.
An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing whitespace could be stored in the cu_log database table such that denial of service occurred for certain CheckUser extension pages and functionality. For example, the attacker could turn off Special:CheckUserLog and thus interfere with usage tracking.
Se detectó un problema en la extensión CheckUser para MediaWiki versiones hasta 1.35.2. Unos nombres de usuario de MediaWiki con espacios en blanco al final podrían ser almacenados en la tabla de la base de datos cu_log de manera que se produjera una denegación de servicio para determinadas páginas de extensión y funcionalidad CheckUser. Por ejemplo, el atacante podría desactivar Special: CheckUserLog y así interferir con el seguimiento del uso
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 6.4 | 10.0 | 4.9 | AV:N/AC:L/Au:N/C:N/I:P/A:P |
| 3.1 | Primary | NVD | 6.5 | 3.9 | 2.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |