MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
References
Configurations
History
No history.
Information
Published : 2012-01-08 11:55
Updated : 2025-04-11 00:51
NVD link : CVE-2011-4361
Mitre link : CVE-2011-4361
CVE.ORG link : CVE-2011-4361
JSON object : View
Products Affected
debian
- debian_linux
mediawiki
- mediawiki
CWE
CWE-276
Incorrect Default Permissions