Mediawiki v1.40.0 does not validate namespaces used in XML files.Therefore, if the instance administrator allows XML file uploads,a remote attacker with a low-privileged user account can use thisexploit to become an administrator by sending a malicious link tothe instance administrator.
{ "cpes": [ "cpe:2.3:a:mediawiki:mediawiki:1.40.0:-:*:*:*:*:*:*" ], "severity": "High" }