PT-2010-2898 · Mediawiki · Mediawiki

Published

2010-03-31

·

Updated

2013-09-13

·

CVE-2010-1190

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.15.2
Description The issue allows remote attackers to bypass intended access restrictions and read private images. This is due to the failure of thumb.php to check user permissions before providing scaled images when used with access-restriction mechanisms.
Recommendations For versions prior to 1.15.2, update to version 1.15.2 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1190
DSA-2022-1

Affected Products

Mediawiki