CVE-2019-12468
10.07.2019, 15:15
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mediawiki | mediawiki | 1.27.0 ≤ 𝑥 ≤ 1.32.1 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mediawiki |
|
Common Weakness Enumeration
References