- EPSS 0.91%
- Published 18.11.2013 02:55:07
- Last modified 11.04.2025 00:51:21
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extens...
CVE-2013-2114
- EPSS 1.4%
- Published 18.11.2013 02:55:07
- Last modified 11.04.2025 00:51:21
Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
- EPSS 0.71%
- Published 27.10.2013 00:55:03
- Last modified 11.04.2025 00:51:21
includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to obtain sensitive information via a "<" (open angle bracket) character in the lang parameter...
- EPSS 0.7%
- Published 27.10.2013 00:55:03
- Last modified 11.04.2025 00:51:21
(1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php in includes/api/ in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 a...
CVE-2013-4305
- EPSS 0.19%
- Published 11.10.2013 21:55:44
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in contrib/example.php in the SyntaxHighlight GeSHi extension for MediaWiki, possibly as downloaded before September 2013, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CVE-2013-4306
- EPSS 0.23%
- Published 11.10.2013 21:55:44
- Last modified 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in api/ApiQueryCheckUser.php in the CheckUser extension for MediaWiki, possibly Checkuser before 2.3, allows remote attackers to hijack the authentication of arbitrary users for requests that "perform s...
CVE-2013-4307
- EPSS 0.42%
- Published 12.09.2013 13:30:39
- Last modified 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in repo/includes/EntityView.php in the Wikibase extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow (1) remote attackers to inject arbitrary web script...
- EPSS 1.18%
- Published 09.09.2012 21:55:07
- Last modified 11.04.2025 00:51:21
The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) via certain input, as demonstrated by the padleft function.
- EPSS 0.58%
- Published 09.09.2012 21:55:06
- Last modified 11.04.2025 00:51:21
The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which allows remote attackers to obtain sensitive information.
CVE-2012-1580
- EPSS 0.3%
- Published 09.09.2012 21:55:06
- Last modified 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload files.