MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not properly restrict access to revisions, which allows remote authenticated users with the viewsuppressed user right to remove revision suppressions via a crafted revisiondelete action, which returns a valid a change form.
References
Link | Resource |
---|---|
http://www.securitytracker.com/id/1034028 | |
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html | Patch Vendor Advisory |
https://phabricator.wikimedia.org/T95589 | Vendor Advisory |
http://www.securitytracker.com/id/1034028 | |
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html | Patch Vendor Advisory |
https://phabricator.wikimedia.org/T95589 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securitytracker.com/id/1034028 - | |
References | () https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html - Patch, Vendor Advisory | |
References | () https://phabricator.wikimedia.org/T95589 - Vendor Advisory |
Information
Published : 2015-11-09 18:59
Updated : 2024-11-21 02:37
NVD link : CVE-2015-8004
Mitre link : CVE-2015-8004
CVE.ORG link : CVE-2015-8004
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE
CWE-264
Permissions, Privileges, and Access Controls