The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.
We have discovered 7,918 live websites that are affected by CVE-2020-27621.
![]() | 2,908 websites |
![]() | 1,558 websites |
![]() | 583 websites |
![]() | 521 websites |
![]() | 216 websites |
![]() | 194 websites |
![]() | 176 websites |
![]() | 115 websites |
![]() | 108 websites |
.com | 1,915 websites |
.org | 1,711 websites |
.de | 727 websites |
.net | 649 websites |
.ru | 420 websites |
.info | 207 websites |
.fr | 148 websites |
.eu | 129 websites |
.nl | 125 websites |
.edu | 84 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.com | ![]() | *,*** | |
****.********.org | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
****.***************.org | ![]() | **,*** | |
**.************.com | ![]() | **,*** | |
****.*******.org | ![]() | **,*** | |
****.*********.org | ![]() | **,*** | |
****.********.org | ![]() | **,*** | |
******.org | ![]() | **,*** | |
******************.org | ![]() | **,*** |