CVE-2019-12468Missing Authentication for Critical Function in Core

Severity
9.8CRITICALNVD
EPSS
0.5%
top 33.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 24

Description

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

Packagistmediawiki/core1.27.01.27.6+3
debiandebian/mediawiki< mediawiki 1:1.31.2-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.31.2-1+3
NVDmediawiki/mediawiki1.27.01.32.1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

3
OSV
Wikimedia MediaWiki Incorrect Access Control vulnerability2022-05-24
GHSA
Wikimedia MediaWiki Incorrect Access Control vulnerability2022-05-24
OSV
CVE-2019-12468: An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 12019-07-10

📋Vendor Advisories

1
Debian
CVE-2019-12468: mediawiki - An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27....2019
CVE-2019-12468 — Mediawiki Core vulnerability | cvebase