Lucene search

K
cvelistMitreCVELIST:CVE-2021-41801
HistoryOct 11, 2021 - 7:40 a.m.

CVE-2021-41801

2021-10-1107:40:22
mitre
www.cve.org
4
replacetext extension
incorrect access control
mediawiki
user blocked
job queue backlog

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

37.0%

The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

37.0%