PT-2019-3450 · Wikimedia+1 · Mediawiki+1

Trijnstel

·

Published

2017-08-22

·

Updated

2025-09-29

·

CVE-2019-12472

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.18.0 through 1.32.1
Description The issue is related to an Incorrect Access Control vulnerability. It allows bypassing the limits on IP range blocks by utilizing the API. This could potentially enable a remote attacker to compromise data integrity.
Recommendations For MediaWiki versions 1.18.0 through 1.32.1, update to version 1.32.2, 1.31.2, 1.30.2, or 1.27.6 to resolve the issue. As a temporary workaround, consider restricting access to the API until the update is applied.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2017-2095
ALT-PU-2019-2016
ALT-PU-2019-2054
BDU:2019-03621
CVE-2019-12472
DSA-4460-1
GHSA-7MQG-5FGH-XH4R
MGASA-2019-0279

Affected Products

Alt Linux
Mediawiki