Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuths account lock
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | 1.31.0 (including) | 1.31.1 (excluding) |
Mediawiki | Mediawiki | 1.27.5 (including) | 1.27.5 (including) |
Mediawiki | Mediawiki | 1.29.3 (including) | 1.29.3 (including) |
Mediawiki | Mediawiki | 1.30.1 (including) | 1.30.1 (including) |