Description
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
Remediation
References
Related Vulnerabilities
WordPress Plugin My Category Order 'parentID' Parameter SQL Injection (2.8)
WordPress Plugin WP Ad Guru Lite Cross-Site Scripting (1.6.0)
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-19520)
Zope Web Application Server Other Vulnerability (CVE-2010-3198)
WordPress Plugin YITH Desktop Notifications for WooCommerce Security Bypass (1.2.7)