MediaWiki Improper Access Control Vulnerability - CVE-2016-6337 - Vulnerability Database

MediaWiki Improper Access Control Vulnerability - CVE-2016-6337

High
Reference: CVE-2016-6337
Title: MediaWiki Improper Access Control Vulnerability
Overview:

MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.