Show filters
373 Total Results
Displaying 191-200 of 373
Sort by:
Attacker Value
Unknown

CVE-2019-12473

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12472

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12466

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki through 1.32.1 allows CSRF.
0
Attacker Value
Unknown

CVE-2019-12468

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
0
Attacker Value
Unknown

CVE-2019-12467

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

Information disclosure in Special:Redirect/logid

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
0
Attacker Value
Unknown

$wgRateLimits entry for 'user' overrides 'newbie'

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.
0
Attacker Value
Unknown

Tarball was missing .htaccess files

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
0
Attacker Value
Unknown

BotPasswords can bypass CentralAuth's account lock

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
0
Attacker Value
Unknown

CVE-2014-1686

Disclosure Date: April 16, 2018 (last updated November 26, 2024)
MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.
0