CVE-2011-4361Incorrect Default Permissions in Mediawiki

Severity
5.0MEDIUMNVD
EPSS
0.2%
top 60.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8
Latest updateMay 13

Description

MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.15.5-4 (bookworm)
NVDmediawiki/mediawiki< 1.17.1
Debianmediawiki/mediawiki< 1:1.15.5-4+3

Also affects: Debian Linux 5.0, 6.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5qr9-g785-2f9v: MediaWiki before 12022-05-13
OSV
CVE-2011-4361: MediaWiki before 12012-01-08

📋Vendor Advisories

1
Debian
CVE-2011-4361: mediawiki - MediaWiki before 1.17.1 does not check for read permission before handling actio...2011

💬Community

1
Bugzilla
CVE-2011-4360 CVE-2011-4361 MediaWiki (x < v.1.17.1): Two information disclosure flaws2011-11-29
CVE-2011-4361 — Incorrect Default Permissions | cvebase