Improper authorization control for web services In mediawiki
Description
Wikimedia MediaWiki Incorrect Access Control vulnerability An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 1:1.31.2-1 | ||
debian 14 | 1:1.31.2-1 | ||
packagist | 1.27.6, 1.30.2, 1.31.2, 1.32.2 | ||
debian 13 | 1:1.31.2-1 | ||
debian 12 | 1:1.31.2-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.