CVE-2014-2665
published 2014-04-20CVE-2014-2665: includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a…
PriorityP415medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.06%
61.0th percentile
includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.19.14+dfsg-1 (bookworm) | mediawiki 1:1.19.14+dfsg-1 (bookworm) |
| mediawiki | mediawiki | <= 1.19.13 | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-2665: mediawiki - includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x ...
vendor_debian·2014·CVSS 4.0
CVE-2014-2665 [MEDIUM] CVE-2014-2665: mediawiki - includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x ...
includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.
Scope: local
bookworm: resolved (fixed in 1:1.19.14+dfsg-1)
bullseye: resolved (fixed in 1:1.19.14+dfsg-1)
forky: resolved (fixed in 1:1.19.14+dfsg-1)
sid: resolved (fixed in 1:1.19.14+dfsg-1)
trixie: resolved (fixed in 1:1.19.14+dfsg-1)
GHSA
GHSA-h9j9-33h5-rrmw: includes/specials/SpecialChangePassword
ghsa_unreviewed·2022-05-17
CVE-2014-2665 [MEDIUM] CWE-287 GHSA-h9j9-33h5-rrmw: includes/specials/SpecialChangePassword
includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.
OSV
CVE-2014-2665: includes/specials/SpecialChangePassword
osv·2014-04-20·CVSS 4.0
CVE-2014-2665 [MEDIUM] CVE-2014-2665: includes/specials/SpecialChangePassword
includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.
No detection rules found.
No public exploits indexed.
http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-March/000145.htmlhttp://openwall.com/lists/oss-security/2014/03/28/1http://openwall.com/lists/oss-security/2014/04/01/7https://bugzilla.wikimedia.org/show_bug.cgi?id=62497https://gerrit.wikimedia.org/r/#/c/121517/1/includes/specials/SpecialChangePassword.phphttp://lists.wikimedia.org/pipermail/mediawiki-announce/2014-March/000145.htmlhttp://openwall.com/lists/oss-security/2014/03/28/1http://openwall.com/lists/oss-security/2014/04/01/7https://bugzilla.wikimedia.org/show_bug.cgi?id=62497https://gerrit.wikimedia.org/r/#/c/121517/1/includes/specials/SpecialChangePassword.php
2014-04-20
Published