Vulnerability Name: | CCN-80347 | ||||||
Published: | 2012-11-28 | ||||||
Updated: | 2012-11-28 | ||||||
Summary: | MediaWiki could allow a remote attacker to bypass security restrictions, caused by an error in improper validation of access permissions.A remote attacker could exploit this vulnerability to bypass security restrictions to restrict users view on Special:RecentChanges page and gain unauthorized access to the vulnerable application. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Bypass Security | ||||||
References: | Source: CCN Type: MediaWiki Web Site Pre-Release Announcement for MediaWiki 1.18.6, 1.19.3, and 1.20.1 Source: CCN Type: SA51424 MediaWiki Security Bypass Vulnerabilities Source: CCN Type: BID-56714 MediaWiki Multiple Security Bypass and HTML Injection Vulnerabilities Source: XF Type: UNKNOWN mediawiki-recentchanges-security-bypass(80347) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |