Description
ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google Authenticator Unspecified Vulnerability (0.47)
WordPress Plugin Viral Quiz Maker-OnionBuzz SQL Injection (1.2.6)
MediaWiki Improper Handling of Exceptional Conditions Vulnerability (CVE-2020-25869)
WordPress Plugin Anti Spam Protection without CAPTCHA powered by Keypic Security Bypass (2.1.2)