Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9hp-7333-625v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by creating crafted wikiUserID and wikiUserName cookies, or by leveraging an unattended workstation.

includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by creating crafted wikiUserID and wikiUserName cookies, or by leveraging an unattended workstation.

EPSS

Процентиль: 56%
0.00331
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 14 лет назад

includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by creating crafted wikiUserID and wikiUserName cookies, or by leveraging an unattended workstation.

nvd
больше 14 лет назад

includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by creating crafted wikiUserID and wikiUserName cookies, or by leveraging an unattended workstation.

debian
больше 14 лет назад

includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogi ...

EPSS

Процентиль: 56%
0.00331
Низкий

Дефекты

CWE-287