CVE-2015-6727 — Sensitive Information Exposure in Mediawiki
Severity
5.0MEDIUMNVD
EPSS
0.4%
top 38.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 1
Latest updateMay 17
Description
The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages3 packages
Also affects: Ubuntu Linux 15.04
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2015-6727: mediawiki - The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before...↗2015
💬Community
1Bugzilla▶
CVE-2013-7444 CVE-2015-6737 CVE-2015-6736 CVE-2015-6727 CVE-2015-6733 CVE-2015-6732 CVE-2015-6731 CVE-2015-6730 CVE-2015-6728 CVE-2015-6729 CVE-2015-6735 CVE-2015-6734 mediawiki: multiple security fix↗2015-08-13