CVE Vulnerabilities

CVE-2013-4302

Published: Oct 27, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

(1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php in includes/api/ in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow remote attackers to obtain CSRF tokens and bypass the cross-site request forgery (CSRF) protection mechanism via a JSONP request to wiki/api.php.

Affected Software

NameVendorStart VersionEnd Version
MediawikiMediawiki1.19.0 (including)1.19.0 (including)
MediawikiMediawiki1.19.1 (including)1.19.1 (including)
MediawikiMediawiki1.19.2 (including)1.19.2 (including)
MediawikiMediawiki1.19.3 (including)1.19.3 (including)
MediawikiMediawiki1.19.4 (including)1.19.4 (including)
MediawikiMediawiki1.19.5 (including)1.19.5 (including)
MediawikiMediawiki1.19.6 (including)1.19.6 (including)
MediawikiMediawiki1.19.7 (including)1.19.7 (including)
MediawikiMediawiki1.20 (including)1.20 (including)
MediawikiMediawiki1.20.1 (including)1.20.1 (including)
MediawikiMediawiki1.20.2 (including)1.20.2 (including)
MediawikiMediawiki1.20.3 (including)1.20.3 (including)
MediawikiMediawiki1.20.4 (including)1.20.4 (including)
MediawikiMediawiki1.20.5 (including)1.20.5 (including)
MediawikiMediawiki1.20.6 (including)1.20.6 (including)
MediawikiMediawiki1.21 (including)1.21 (including)
MediawikiMediawiki1.21.1 (including)1.21.1 (including)
MediawikiUbuntuartful*
MediawikiUbuntulucid*
MediawikiUbuntuprecise*
MediawikiUbuntuquantal*
MediawikiUbunturaring*
MediawikiUbuntusaucy*
MediawikiUbuntuupstream*
MediawikiUbuntuutopic*
MediawikiUbuntuvivid*
MediawikiUbuntuwily*
MediawikiUbuntuyakkety*
MediawikiUbuntuzesty*

References