7.5
CVSSv2

CVE-2015-6728

Published: 01/09/2015 Updated: 07/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ApiBase::getWatchlistUser function in MediaWiki prior to 1.23.10, 1.24.x prior to 1.24.3, and 1.25.x prior to 1.25.2 does not perform token comparison in constant time, which allows remote malicious users to guess the watchlist token and bypass CSRF protection via a timing attack.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.24.1

mediawiki mediawiki 1.24.2

mediawiki mediawiki

mediawiki mediawiki 1.24.0

mediawiki mediawiki 1.25.1

mediawiki mediawiki 1.25.0

Vendor Advisories

Debian Bug report logs - #799096 mediawiki: CVE-2013-7444 CVE-2015-6727 CVE-2015-6728 CVE-2015-6730 Package: src:mediawiki; Maintainer for src:mediawiki is Kunal Mehta <legoktm@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 15 Sep 2015 20:15:02 UTC Severity: important Tags: security, up ...