Summary
MediaWiki is prone to an information-disclosure vulnerability because it fails to properly restrict the posting of remote images.
An attacker can exploit this vulnerability to have users view remote images, which may aid in further attacks.
Versions prior to MediaWiki 1.15.2 are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Severity
Classification
-
CVE CVE-2010-1189 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities