7.5
CVSSv2

CVE-2013-4304

Published: 26/01/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The CentralAuth extension for MediaWiki 1.19.x prior to 1.19.8, 1.20.x prior to 1.20.7, and 1.21.x prior to 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote malicious users to bypass authentication without a password.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.19.6

mediawiki mediawiki 1.19.5

mediawiki mediawiki 1.19

mediawiki mediawiki 1.21.1

mediawiki mediawiki 1.21

brion vibber centralauth extension -

mediawiki mediawiki 1.19.7

mediawiki mediawiki 1.19.0

mediawiki mediawiki 1.20.2

mediawiki mediawiki 1.20.1

mediawiki mediawiki 1.20

mediawiki mediawiki 1.19.2

mediawiki mediawiki 1.19.1

mediawiki mediawiki 1.20.4

mediawiki mediawiki 1.20.3

mediawiki mediawiki 1.19.4

mediawiki mediawiki 1.19.3

mediawiki mediawiki 1.20.6

mediawiki mediawiki 1.20.5