Description
An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for the mainpage message.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2018-1333)
WordPress Plugin WP Fastest Cache Cross-Site Request Forgery (0.8.3.4)
WEBrick v.1.3 directory traversal
Dotclear Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3232)
WordPress Plugin WP AutoComplete Search SQL Injection (1.0.4)