6.8
CVSSv2

CVE-2015-8623

Published: 23/03/2017 Updated: 27/03/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The User::matchEditToken function in includes/User.php in MediaWiki prior to 1.23.12 and 1.24.x prior to 1.24.5 does not perform token comparison in constant time before returning, which allows remote malicious users to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki

mediawiki mediawiki 1.24.0

mediawiki mediawiki 1.24.1

mediawiki mediawiki 1.24.2

mediawiki mediawiki 1.24.4

mediawiki mediawiki 1.24.3