Lucene search

K
osvGoogleOSV:CVE-2021-41801
HistoryOct 11, 2021 - 8:15 a.m.

CVE-2021-41801

2021-10-1108:15:06
Google
osv.dev
10
replacetext extension
mediawiki
incorrect access control
job queue backlog

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

37.0%

The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

37.0%