Vulnerability Name: | CVE-2015-8625 |
Assigned: | 2015-12-23 |
Published: | 2017-03-23 |
Updated: | 2017-03-27 |
Summary: | MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters.
|
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): None Availibility (A): None | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-200
|
References: | Source: MITRE Type: CNA CVE-2015-8625
Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20151221 CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12
Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20151223 Re: CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12
Source: MLIST Type: Patch, Release Notes, Vendor Advisory [MediaWiki-announce] 20151221 [MediaWiki-announce] Security Release: 1.26.1, 1.25.4, 1.24.5 and 1.23.12
Source: CONFIRM Type: Patch, Third Party Advisory https://phabricator.wikimedia.org/T118032
|
Vulnerable Configuration: | Configuration 1: cpe:/a:mediawiki:mediawiki:*:*:*:*:*:*:*:* (Version <= 1.23.11)OR cpe:/a:mediawiki:mediawiki:1.24.0:*:*:*:*:*:*:*OR cpe:/a:mediawiki:mediawiki:1.24.1:*:*:*:*:*:*:*OR cpe:/a:mediawiki:mediawiki:1.24.2:*:*:*:*:*:*:*OR cpe:/a:mediawiki:mediawiki:1.24.3:*:*:*:*:*:*:*OR cpe:/a:mediawiki:mediawiki:1.24.4:*:*:*:*:*:*:*OR cpe:/a:mediawiki:mediawiki:1.25.0:*:*:*:*:*:*:*OR cpe:/a:mediawiki:mediawiki:1.25.1:*:*:*:*:*:*:*OR cpe:/a:mediawiki:mediawiki:1.25.2:*:*:*:*:*:*:*OR cpe:/a:mediawiki:mediawiki:1.25.3:*:*:*:*:*:*:*OR cpe:/a:mediawiki:mediawiki:1.26.0:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |