Summary
MediaWiki is prone to a security-bypass vulnerability because it fails to properly restrict access to restricted content.
An attacker can exploit this issue to bypass intended security measures to view restricted content in private wikis.
Versions after MediaWiki 1.15 and prior to MediaWiki 1.15.2 are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Severity
Classification
-
CVSS Base Score: 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:N
Related Vulnerabilities
- 123 Flash Chat Multiple Security Vulnerabilities
- 2532|Gigs Directory Traversal And SQL Injection Multiple Vulnerabilities
- Adobe ColdFusion Unspecified Information Disclosure Vulnerability
- Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
- Allegro RomPager HTTP Referer Header Cross Site Scripting Vulnerability