CVE-2015-8009
- EPSS 0.34%
- Veröffentlicht 25.07.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not properly validate the signature when checking the authorization signature, which allows remote regist...
CVE-2016-6331
- EPSS 0.17%
- Veröffentlicht 20.04.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.
CVE-2016-6332
- EPSS 0.22%
- Veröffentlicht 20.04.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain sensitive information by leveraging failure to terminate sessions when a user account is blocked.
CVE-2016-6333
- EPSS 0.34%
- Veröffentlicht 20.04.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:My...
CVE-2016-6334
- EPSS 0.22%
- Veröffentlicht 20.04.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving repl...
CVE-2016-6335
- EPSS 0.27%
- Veröffentlicht 20.04.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php.
CVE-2016-6336
- EPSS 0.11%
- Veröffentlicht 20.04.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete permissions to bypass intended suppressrevision and deleterevision restrictions and remove the revision deletion status of arbitr...
CVE-2016-6337
- EPSS 0.34%
- Veröffentlicht 20.04.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.
CVE-2015-8622
- EPSS 0.3%
- Veröffentlicht 23.03.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1, when is configured with a relative URL, allows remote authenticated users to inject arbitrary web script or HT...
CVE-2015-8623
- EPSS 0.13%
- Veröffentlicht 23.03.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF pro...