Description
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Post Type UI 'wp-admin/admin.php' Cross-Site Scripting (0.7)
WordPress Plugin CMS Tree Page View Cross-Site Scripting (1.2.31)
MySQL CVE-2014-4207 Vulnerability (CVE-2014-4207)
Joomla Improper Input Validation Vulnerability (CVE-2020-11890)
WordPress Plugin WordPress File Upload Directory Traversal (4.12.2)