Description
In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contact Form 7 Database Information Disclosure (1.3)
GlassFish CVE-2018-3210 Vulnerability (CVE-2018-3210)
WordPress Plugin Pro Quoter Multiple Cross-Site Scripting Vulnerabilities (1.0)
WordPress Plugin Event Management Tickets Booking By Event Monster Cross-Site Scripting (1.0.7)
Jenkins Improper Authentication Vulnerability (CVE-2014-2062)