Show filters
381 Total Results
Displaying 191-200 of 381
Sort by:
Attacker Value
Unknown
CVE-2019-19709
Disclosure Date: August 08, 2019 (last updated November 27, 2024)
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
0
Attacker Value
Unknown
CVE-2019-12469
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown
CVE-2019-12470
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown
CVE-2019-12471
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown
CVE-2019-12474
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown
CVE-2019-12473
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown
CVE-2019-12472
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown
CVE-2019-12466
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki through 1.32.1 allows CSRF.
0
Attacker Value
Unknown
CVE-2019-12468
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
0
Attacker Value
Unknown
CVE-2019-12467
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0