Lucene search

K
osvGoogleOSV:CVE-2020-35477
HistoryDec 18, 2020 - 8:15 a.m.

CVE-2020-35477

2020-12-1808:15:15
Google
osv.dev
9
mediawiki
log entry
visibility

AI Score

6.4

Confidence

High

EPSS

0.002

Percentile

60.8%

MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the “Change visibility of selected log entries” checkbox (or a tags checkbox) next to it, there is a redirection to the main page’s action=historysubmit (instead of the desired behavior in which a revision-deletion form appears).