4
CVSSv2

CVE-2014-2665

Published: 20/04/2014 Updated: 24/04/2014
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

includes/specials/SpecialChangePassword.php in MediaWiki prior to 1.19.14, 1.20.x and 1.21.x prior to 1.21.8, and 1.22.x prior to 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.22.3

mediawiki mediawiki 1.22.2

mediawiki mediawiki 1.21.2

mediawiki mediawiki 1.21.3

mediawiki mediawiki 1.20.5

mediawiki mediawiki 1.20.6

mediawiki mediawiki 1.19

mediawiki mediawiki 1.19.0

mediawiki mediawiki 1.19.6

mediawiki mediawiki 1.19.7

mediawiki mediawiki 1.21.6

mediawiki mediawiki 1.21.5

mediawiki mediawiki 1.20.1

mediawiki mediawiki 1.20.2

mediawiki mediawiki

mediawiki mediawiki 1.19.12

mediawiki mediawiki 1.19.2

mediawiki mediawiki 1.19.3

mediawiki mediawiki 1.22.4

mediawiki mediawiki 1.21

mediawiki mediawiki 1.21.1

mediawiki mediawiki 1.20.3

mediawiki mediawiki 1.20.4

mediawiki mediawiki 1.19.11

mediawiki mediawiki 1.19.4

mediawiki mediawiki 1.19.5

mediawiki mediawiki 1.22.0

mediawiki mediawiki 1.22.1

mediawiki mediawiki 1.21.7

mediawiki mediawiki 1.21.4

mediawiki mediawiki 1.20

mediawiki mediawiki 1.20.7

mediawiki mediawiki 1.20.8

mediawiki mediawiki 1.19.1

mediawiki mediawiki 1.19.10

mediawiki mediawiki 1.19.8

mediawiki mediawiki 1.19.9

Vendor Advisories

Several vulnerabilities were discovered in MediaWiki, a wiki engine The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-2031 Cross-site scripting attack via valid UTF-7 encoded sequences in a SVG file CVE-2013-4567 & CVE-2013-4568 Kevin Israel (Wikipedia user PleaseStand) reported two wa ...