VOOZH about

URL: https://github.com/advisories/GHSA-6vfg-8ppv-h5hg

⇱ MediaWiki Incorrect Access Control vulnerability · CVE-2019-12467 · GitHub Advisory Database · GitHub


Skip to content

MediaWiki Incorrect Access Control vulnerability

Moderate severity GitHub Reviewed Published to the GitHub Advisory Database • Updated

Package

mediawiki/core (Composer)

Affected versions

< 1.27.6
>= 1.30.0, < 1.30.2
>= 1.31.0, < 1.31.2
>= 1.32.0, < 1.32.2

Patched versions

1.27.6
1.30.2
1.31.2
1.32.2

Description

MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

References

Published to the GitHub Advisory Database
Last updated
Reviewed

Severity

Moderate
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS score

(66th percentile)

Weaknesses

CVE ID

CVE-2019-12467

GHSA ID

GHSA-6vfg-8ppv-h5hg

Source code

See something to contribute? Suggest improvements for this vulnerability.
You can’t perform that action at this time.