Description
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-2617 Vulnerability (CVE-2015-2617)
WordPress Plugin BLAZE Retail Widget Malicious Code (2.5.2)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4297)
WordPress Plugin LOGOSWARE SUITE Uploader Arbitrary File Upload (1.1.6)
Oracle Database Server CVE-2010-3590 Vulnerability (CVE-2010-3590)