All errata/p7/ALT-PU-2014-1972-1
ALT-PU-2014-1972-1

Package update mediawiki in branch p7

Version1.23.1-alt0.M70P.1
Published2014-08-02
Max severityMEDIUM
Severity:

Closed issues (3)

CVE-2014-2665
MEDIUM4.0

includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.

Published: 2014-04-20Modified: 2025-04-12
CVSS 2.0MEDIUM 4.0
CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:N/A:N