Show filters
381 Total Results
Displaying 191-200 of 381
Sort by:
Attacker Value
Unknown

CVE-2019-19709

Disclosure Date: August 08, 2019 (last updated November 27, 2024)
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
Attacker Value
Unknown

CVE-2019-12469

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12470

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12471

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12474

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12473

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12472

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12466

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki through 1.32.1 allows CSRF.
0
Attacker Value
Unknown

CVE-2019-12468

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
0
Attacker Value
Unknown

CVE-2019-12467

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0