PT-2011-3234 · Wikimedia · Mediawiki

Happy-Melon

·

Published

2011-04-27

·

Updated

2017-08-17

·

CVE-2011-1580

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.16.3
Description The issue concerns the transwiki import functionality, which does not properly check privileges. This allows remote authenticated users to perform imports from any wgImportSources wiki via a crafted POST request.
Recommendations For versions prior to 1.16.3, update to version 1.16.3 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1580
DSA-2366-1

Affected Products

Mediawiki