CVE-2013-2114

MediaWiki 1.19-1.19.6 and 1.20.x < 1.20.6 - Unauthenticated Remote Code Execution via Chunk Upload API

Title source: llm
STIX 2.1

Description

Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55433
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/05/24/3
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201310-21.xml

Scores

EPSS 0.0140
EPSS Percentile 80.7%

Details

Status published
Products (13)
mediawiki/mediawiki 1.19 (3 CPE variants)
mediawiki/mediawiki 1.19.0
mediawiki/mediawiki 1.19.1
mediawiki/mediawiki 1.19.2
mediawiki/mediawiki 1.19.3
mediawiki/mediawiki 1.19.4
mediawiki/mediawiki 1.19.5
mediawiki/mediawiki 1.19.6
mediawiki/mediawiki 1.20.1
mediawiki/mediawiki 1.20.2
... and 3 more
Published Nov 18, 2013
Tracked Since Feb 18, 2026