Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

MediaWiki Arbitrary File Upload Vulnerability

High

Synopsis

The remote web server is running a PHP application that is affected by a cross-site scripting vulnerability.

Description

The remote web server is running MediaWiki.

The application is prone to an arbitrary file-upload vulnerability because it fails to adequately validate files before uploading them to the vulnerable server. An attacker can exploit this issue to upload a chunk file through API.

Solution

Upgrade to MediaWiki version 1.20.6, 1.19.7, or higher.