Medium severity4.4NVD Advisory· Published Sep 19, 2022· Updated Jun 17, 2026
CVE-2022-28201
CVE-2022-28201
Description
An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for the mainpage message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Range: <1.35.6, <1.36.4, <1.37.2
Patches
Vulnerability mechanics
References
4- phabricator.wikimedia.org/T297571nvdPatchVendor Advisory
- blog.legoktm.com/2022/07/03/a-belated-writeup-of-cve-2022-28201-in-mediawiki.htmlnvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/09/msg00027.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2022/dsa-5246nvdThird Party Advisory
News mentions
0No linked articles in our index yet.