5
CVSSv2

CVE-2013-4302

Published: 27/10/2013 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

(1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php in includes/api/ in MediaWiki 1.19.x prior to 1.19.8, 1.20.x prior to 1.20.7, and 1.21.x prior to 1.21.2 allow remote malicious users to obtain CSRF tokens and bypass the cross-site request forgery (CSRF) protection mechanism via a JSONP request to wiki/api.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.20.3

mediawiki mediawiki 1.20.4

mediawiki mediawiki 1.19.4

mediawiki mediawiki 1.19.5

mediawiki mediawiki 1.20.1

mediawiki mediawiki 1.20.2

mediawiki mediawiki 1.19.2

mediawiki mediawiki 1.19.3

mediawiki mediawiki 1.21.1

mediawiki mediawiki 1.20

mediawiki mediawiki 1.19.0

mediawiki mediawiki 1.19.1

mediawiki mediawiki 1.21

mediawiki mediawiki 1.20.5

mediawiki mediawiki 1.20.6

mediawiki mediawiki 1.19.6

mediawiki mediawiki 1.19.7

Vendor Advisories

It was discovered that in Mediawiki, a wiki engine, several API modules allowed anti-CSRF tokens to be accessed via JSONP These tokens protect against cross site request forgeries and are confidential For the oldstable distribution (squeeze), this problem has been fixed in version 1155-2squeeze6 For the stable distribution (wheezy), this probl ...