CVE-2020-35477

MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" checkbox (or a tags checkbox) next to it, there is a redirection to the main page's action=historysubmit (instead of the desired behavior in which a revision-deletion form appears).


We have discovered 7,918 live websites that are affected by CVE-2020-35477.

Test my site




Affected Software

Product  MediaWiki
Category Wikis
Vulnerable Domains7,918 live websites (43.62% of MediaWiki install base)
Vulnerable Versions
  • from 0 before 1.35.1
Vulnerable Versions Count172 versions ( 73.50% of all versions)



Details

  • Published - Dec 18, 2020
  • Updated - Aug 4, 2024

CVE-2020-35477 usage by Country

United States2,908 websites



Germany1,558 websites
France583 websites
Russia521 websites
Netherlands216 websites
Singapore194 websites
GB176 websites
Switzerland115 websites
Canada108 websites

CVE-2020-35477 usage by TLD

.com1,915 websites
.org1,711 websites
.de727 websites
.net649 websites
.ru420 websites
.info207 websites
.fr148 websites
.eu129 websites
.nl125 websites
.edu84 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-35477

Top websites that are affected by CVE-2020-35477. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
****.********.org United States*,***
*******.com United States*,***
****.***************.org United States**,***
**.************.com United States**,***
****.*******.org Canada**,***
****.*********.org United States**,***
****.********.org Germany**,***
******.org United States**,***
******************.org Germany**,***
See full domain list

FAQ

A total of 7,918 websites have been identified as vulnerable to CVE-2020-35477, discovered through global website indexing conducted by WebTechSurvey.
MediaWiki is susceptible to CVE-2020-35477 vulnerability.
MediaWiki versions before 1.35.1 are vulnerable to CVE-2020-35477.
Version 1.35.1 of MediaWiki addresses the CVE-2020-35477 security vulnerability.