MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not throttle file uploads, which allows remote authenticated users to have unspecified impact via multiple file uploads.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1034028 | vdb entry |
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html | patch vendor advisory mailing list |
https://phabricator.wikimedia.org/T91850 | vendor advisory |