CVE-2008-5688Sensitive Information Exposure in Mediawiki

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 40.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19
Latest updateMay 17

Description

MediaWiki 1.8.1, and other versions before 1.13.3, when the wgShowExceptionDetails variable is enabled, sometimes provides the full installation path in a debugging message, which might allow remote attackers to obtain sensitive information via unspecified requests that trigger an uncaught exception.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.13.3-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.13.3-1+3
NVDmediawiki/mediawiki27 versions+26

🔴Vulnerability Details

2
GHSA
GHSA-734c-2q7q-jhcc: MediaWiki 12022-05-17
OSV
CVE-2008-5688: MediaWiki 12008-12-19

📋Vendor Advisories

1
Debian
CVE-2008-5688: mediawiki - MediaWiki 1.8.1, and other versions before 1.13.3, when the wgShowExceptionDetai...2008

💬Community

1
Bugzilla
mediawiki: multiple XSS and CSRF issues (CVE-2008-5249, CVE-2008-5250, CVE-2008-5252, CVE-2008-5687, CVE-2008-5688)2008-12-16
CVE-2008-5688 — Sensitive Information Exposure | cvebase