CVE-2011-4361
published 2012-01-08CVE-2011-4361: MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.62%
83.9th percentile
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.15.5-4 (bookworm) | mediawiki 1:1.15.5-4 (bookworm) |
| mediawiki | mediawiki | < 1.17.1 | 1.17.1 |
| mediawiki | mediawiki | >= 0 < 1:1.15.5-4 | 1:1.15.5-4 |
| mediawiki | mediawiki | >= 0 < 1:1.15.5-4 | 1:1.15.5-4 |
| mediawiki | mediawiki | >= 0 < 1:1.15.5-4 | 1:1.15.5-4 |
| mediawiki | mediawiki | >= 0 < 1:1.15.5-4 | 1:1.15.5-4 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5qr9-g785-2f9v: MediaWiki before 1
ghsa_unreviewed·2022-05-13
CVE-2011-4361 [MEDIUM] CWE-276 GHSA-5qr9-g785-2f9v: MediaWiki before 1
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
OSV
CVE-2011-4361: MediaWiki before 1
osv·2012-01-08·CVSS 5.0
CVE-2011-4361 [MEDIUM] CVE-2011-4361: MediaWiki before 1
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
Debian
CVE-2011-4361: mediawiki - MediaWiki before 1.17.1 does not check for read permission before handling actio...
vendor_debian·2011·CVSS 5.0
CVE-2011-4361 [MEDIUM] CVE-2011-4361: mediawiki - MediaWiki before 1.17.1 does not check for read permission before handling actio...
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
Scope: local
bookworm: resolved (fixed in 1:1.15.5-4)
bullseye: resolved (fixed in 1:1.15.5-4)
forky: resolved (fixed in 1:1.15.5-4)
sid: resolved (fixed in 1:1.15.5-4)
trixie: resolved (fixed in 1:1.15.5-4)
No detection rules found.
No public exploits indexed.
http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.htmlhttp://openwall.com/lists/oss-security/2011/11/29/12http://openwall.com/lists/oss-security/2011/11/29/6http://www.debian.org/security/2011/dsa-2366https://bugzilla.redhat.com/show_bug.cgi?id=758171https://bugzilla.wikimedia.org/show_bug.cgi?id=32616http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.htmlhttp://openwall.com/lists/oss-security/2011/11/29/12http://openwall.com/lists/oss-security/2011/11/29/6http://www.debian.org/security/2011/dsa-2366https://bugzilla.redhat.com/show_bug.cgi?id=758171https://bugzilla.wikimedia.org/show_bug.cgi?id=32616
2012-01-08
Published