← Back

CVE-2012-5394

nvd nist
Published: Dec 13, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to hijack the authentication of users for requests that login via vectors involving image loading.

Affected (23)

Products: Mediawiki: Mediawiki
1 product
Mediawiki
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Version 1.20.1
Version 1.20.2
Version 1.20.3
Version 1.20.4
Version 1.20.5
Version 1.20.6
Version 1.20.7
Version 1.20
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Version 1.21.1
Version 1.21.2
Version 1.21
Configuration C
12 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Up to 1.19.8
Version 1.19.0
Version 1.19.1
Version 1.19.2
Version 1.19.3
Version 1.19.4
Version 1.19.5
Version 1.19.6
Version 1.19.7
Version 1.19
Version 1.19 beta_1
Version 1.19 beta_2

Timeline

No history available yet.