Description In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items. Remediation References CVE-2021-45471 Related Vulnerabilities WordPress Plugin Simple JWT Login-Login and Register to WordPress using JWT Insecure Password Creation (3.2.1) Moodle Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2015-1493) PHP Out-of-bounds Read Vulnerability (CVE-2017-9224) Oracle Database Server CVE-2009-1965 Vulnerability (CVE-2009-1965) Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2017-2670) Severity Medium Classification CVE-2021-45471 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Tags Missing Update Known Vulnerabilities