CVE-2011-4360Sensitive Information Exposure in Mediawiki

Severity
5.0MEDIUMNVD
EPSS
0.6%
top 30.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8
Latest updateMay 13

Description

MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.15.5-4 (bookworm)
NVDmediawiki/mediawiki< 1.17.1
Debianmediawiki/mediawiki< 1:1.15.5-4+3

Also affects: Debian Linux 5.0, 6.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mw24-gxjp-j73j: MediaWiki before 12022-05-13
OSV
CVE-2011-4360: MediaWiki before 12012-01-08

📋Vendor Advisories

1
Debian
CVE-2011-4360: mediawiki - MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all...2011

💬Community

1
Bugzilla
CVE-2011-4360 CVE-2011-4361 MediaWiki (x < v.1.17.1): Two information disclosure flaws2011-11-29
CVE-2011-4360 — Sensitive Information Exposure | cvebase