CVE Vulnerabilities

CVE-2013-4302

Published: Oct 27, 2013 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

(1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php in includes/api/ in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow remote attackers to obtain CSRF tokens and bypass the cross-site request forgery (CSRF) protection mechanism via a JSONP request to wiki/api.php.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki 1.19.0 (including) 1.19.0 (including)
Mediawiki Mediawiki 1.19.1 (including) 1.19.1 (including)
Mediawiki Mediawiki 1.19.2 (including) 1.19.2 (including)
Mediawiki Mediawiki 1.19.3 (including) 1.19.3 (including)
Mediawiki Mediawiki 1.19.4 (including) 1.19.4 (including)
Mediawiki Mediawiki 1.19.5 (including) 1.19.5 (including)
Mediawiki Mediawiki 1.19.6 (including) 1.19.6 (including)
Mediawiki Mediawiki 1.19.7 (including) 1.19.7 (including)
Mediawiki Mediawiki 1.20 (including) 1.20 (including)
Mediawiki Mediawiki 1.20.1 (including) 1.20.1 (including)
Mediawiki Mediawiki 1.20.2 (including) 1.20.2 (including)
Mediawiki Mediawiki 1.20.3 (including) 1.20.3 (including)
Mediawiki Mediawiki 1.20.4 (including) 1.20.4 (including)
Mediawiki Mediawiki 1.20.5 (including) 1.20.5 (including)
Mediawiki Mediawiki 1.20.6 (including) 1.20.6 (including)
Mediawiki Mediawiki 1.21 (including) 1.21 (including)
Mediawiki Mediawiki 1.21.1 (including) 1.21.1 (including)

References