Description
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain sensitive information by leveraging failure to terminate sessions when a user account is blocked.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Frequently Bought Together Security Bypass (1.2.10)
WordPress Plugin Convert Docx2post Arbitrary File Upload (1.4)
Microsoft SQL Server Other Vulnerability (CVE-2001-0879)
Jetpack 2.9.3: Critical Security Update
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-0299)