CVE-2015-8008
29.12.2017, 22:29
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.Enginsight
Vendor | Product | Version |
---|---|---|
mediawiki | mediawiki | 𝑥 < 1.25.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References