Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Shpdg

#22841of 53,624
10Total CVSS
Vulnerabilities · 1
PT-2020-14240
10
2020-08-28
Mediawiki · Scratch Login · CVE-2020-15164
**Name of the Vulnerable Software and Affected Versions** Scratch Login (MediaWiki extension) versions prior to 1.1 **Description** The issue allows any account to be logged into by using the same username with leading, trailing, or repeated underscore(s), as these are treated as whitespace and trimmed by MediaWiki. This affects all users on any wiki using the Scratch Login extension. **Recommendations** For versions prior to 1.1, update to version 1.1 or later to resolve the issue.