CVE Vulnerabilities

CVE-2015-8004

Published: Nov 09, 2015 | Modified: Nov 10, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not properly restrict access to revisions, which allows remote authenticated users with the viewsuppressed user right to remove revision suppressions via a crafted revisiondelete action, which returns a valid a change form.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.23.10 (including)
Mediawiki Mediawiki 1.24.0 (including) 1.24.0 (including)
Mediawiki Mediawiki 1.24.1 (including) 1.24.1 (including)
Mediawiki Mediawiki 1.24.2 (including) 1.24.2 (including)
Mediawiki Mediawiki 1.24.3 (including) 1.24.3 (including)
Mediawiki Mediawiki 1.25.0 (including) 1.25.0 (including)
Mediawiki Mediawiki 1.25.1 (including) 1.25.1 (including)
Mediawiki Mediawiki 1.25.2 (including) 1.25.2 (including)

References