MediaWiki < 1.35.2 Oauth Overlength Rsa Key

According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.35.2. It is, therefore, affected by a vulnerability in the Oauth MWOAuthConsumerSubmitContro.php page which does not ensure that the length of supplied RSA key will fit in a MySQL blob.

Note that the scanner has not tested for these issues but has instead relied only on the application’s self-reported version number.Read More

Back to Main

Subscribe for the latest news:
%d bloggers like this: