CVE-2015-8003

MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not throttle file uploads, which allows remote authenticated users to have unspecified impact via multiple file uploads.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.24.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.24.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.24.2:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.24.3:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.25.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.25.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.25.2:*:*:*:*:*:*:*

History

21 Nov 2024, 02:37

Type Values Removed Values Added
References () http://www.securitytracker.com/id/1034028 - () http://www.securitytracker.com/id/1034028 -
References () https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html - Patch, Vendor Advisory () https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html - Patch, Vendor Advisory
References () https://phabricator.wikimedia.org/T91850 - Vendor Advisory () https://phabricator.wikimedia.org/T91850 - Vendor Advisory

Information

Published : 2015-11-09 18:59

Updated : 2024-11-21 02:37


NVD link : CVE-2015-8003

Mitre link : CVE-2015-8003

CVE.ORG link : CVE-2015-8003


JSON object : View

Products Affected

mediawiki

  • mediawiki
CWE
CWE-399

Resource Management Errors