CVE-2015-6727Sensitive Information Exposure in Mediawiki

Severity
5.0MEDIUMNVD
EPSS
0.4%
top 38.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 1
Latest updateMay 17

Description

The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.25.5-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.25.5-1+3
NVDmediawiki/mediawiki1.23.9+5

Also affects: Ubuntu Linux 15.04

🔴Vulnerability Details

2
GHSA
GHSA-v8xm-gjch-p94q: The Special:DeletedContributions page in MediaWiki before 12022-05-17
OSV
CVE-2015-6727: The Special:DeletedContributions page in MediaWiki before 12015-09-01

📋Vendor Advisories

1
Debian
CVE-2015-6727: mediawiki - The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before...2015

💬Community

1
Bugzilla
CVE-2013-7444 CVE-2015-6737 CVE-2015-6736 CVE-2015-6727 CVE-2015-6733 CVE-2015-6732 CVE-2015-6731 CVE-2015-6730 CVE-2015-6728 CVE-2015-6729 CVE-2015-6735 CVE-2015-6734 mediawiki: multiple security fix2015-08-13
CVE-2015-6727 — Sensitive Information Exposure | cvebase