Skip to content

1.1.0.3 - security release for legacy MediaWiki 1.23 (obsolete LTS)

Compare
Choose a tag to compare
@edwardspec edwardspec released this 23 Apr 21:59

Versions 1.1.0.x are bugfix releases that still support MediaWiki 1.23.

Unlike Moderation 1.2.0, this release has no changes except those needed for security.
If you are at MediaWiki 1.27+, please use Moderation 1.2.0.

Changes in Moderation 1.1.0.3 since Moderation 1.1.0

Security updates:

  • Restricted filerevert API (revert image to older version) to automoderated
    users, because this action can't be intercepted by Moderation.
  • Fixed improper escaping of user-provided mod_comment on Special:Moderation.