6.8
CVSSv2

CVE-2012-1578

Published: 09/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in MediaWiki 1.17.x prior to 1.17.3 and 1.18.x prior to 1.18.2 allow remote malicious users to hijack the authentication of users with the block permission for requests that (1) block a user via a request to the Block module or (2) unblock a user via a request to the Unblock module.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.17.1

mediawiki mediawiki 1.17.2

mediawiki mediawiki 1.17

mediawiki mediawiki 1.17.0

mediawiki mediawiki 1.18

mediawiki mediawiki 1.18.0

mediawiki mediawiki 1.18.1

Vendor Advisories

Debian Bug report logs - #666269 mediawiki: security release CVE-2012-1578/CVE-2012-1579/CVE-2012-1580/CVE-2012-1581/CVE-2012-1582 Package: mediawiki; Maintainer for mediawiki is Kunal Mehta <legoktm@debianorg>; Source for mediawiki is src:mediawiki (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: ...