Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sudozero

#35419of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2020-17370
7.5
2020-12-21
Mediawiki · Mediawiki Casauth Extension · CVE-2020-35623
**Name of the Vulnerable Software and Affected Versions** MediaWiki CasAuth extension versions through 1.35.1 **Description** An issue was discovered due to improper username validation, allowing user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able to login as a "bureaucrat user" who has a similar username, as demonstrated by usernames that differ only in bidirectional override symbols or blank space. **Recommendations** For MediaWiki CasAuth extension versions through 1.35.1, update to a version that fixes the improper username validation issue to prevent user impersonation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.