CVE-2013-2032
published 2013-11-18CVE-2013-2032: MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.51%
83.0th percentile
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.19.6-1 (bookworm) | mediawiki 1:1.19.6-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mediawiki | mediawiki | <= 1.19.5 | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-2032: mediawiki - MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to pr...
vendor_debian·2013·CVSS 5.0
CVE-2013-2032 [MEDIUM] CVE-2013-2032: mediawiki - MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to pr...
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.
Scope: local
bookworm: resolved (fixed in 1:1.19.6-1)
bullseye: resolved (fixed in 1:1.19.6-1)
forky: resolved (fixed in 1:1.19.6-1)
sid: resolved (fixed in 1:1.19.6-1)
trixie: resolved (fixed in 1:1.19.6-1)
GHSA
GHSA-jw49-q332-x9hh: MediaWiki before 1
ghsa_unreviewed·2022-05-17
CVE-2013-2032 [MEDIUM] GHSA-jw49-q332-x9hh: MediaWiki before 1
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.
OSV
CVE-2013-2032: MediaWiki before 1
osv·2013-11-18·CVSS 5.0
CVE-2013-2032 [MEDIUM] CVE-2013-2032: MediaWiki before 1
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105784.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105825.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/106293.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000129.htmlhttp://secunia.com/advisories/55433http://security.gentoo.org/glsa/glsa-201310-21.xmlhttps://bugzilla.wikimedia.org/show_bug.cgi?id=46590http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105784.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105825.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/106293.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000129.htmlhttp://secunia.com/advisories/55433http://security.gentoo.org/glsa/glsa-201310-21.xmlhttps://bugzilla.wikimedia.org/show_bug.cgi?id=46590
2013-11-18
Published