The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.31.16"
},
{
"introduced": "1.35.0"
},
{
"fixed": "1.35.4"
},
{
"introduced": "1.36.0"
},
{
"fixed": "1.36.2"
}
],
"cpe": "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*"
}