CVE-2011-4361: Medium severity mediawiki vulnerability
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4361?
CVE-2011-4361 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2011-4361?
To fix CVE-2011-4361, update MediaWiki to version 1.17.1 or later where this vulnerability has been addressed.
What types of attacks can be conducted using CVE-2011-4361?
CVE-2011-4361 allows remote attackers to obtain sensitive information by exploiting unprotected AJAX requests.
Which versions of MediaWiki are affected by CVE-2011-4361?
MediaWiki versions before 1.17.1 are vulnerable to CVE-2011-4361.
Is any configuration required to mitigate CVE-2011-4361?
No specific configuration is required to mitigate CVE-2011-4361 other than upgrading to a secure version of MediaWiki.