CVE-2012-1578: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allow remote attackers to hijack the authentication of users with the block permission for requests that (1) block a user via a request to the Block module or (2) unblock a user via a request to the Unblock module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1578?
CVE-2012-1578 is classified with a medium severity level due to the potential for account hijacking.
How do I fix CVE-2012-1578?
To fix CVE-2012-1578, upgrade MediaWiki to version 1.17.3 or 1.18.2 or later.
What types of attacks are possible with CVE-2012-1578?
CVE-2012-1578 allows attackers to perform cross-site request forgery (CSRF) attacks to manipulate user-blocking actions.
Which MediaWiki versions are affected by CVE-2012-1578?
MediaWiki versions 1.17.x before 1.17.3 and 1.18.x before 1.18.2 are affected by CVE-2012-1578.
Who is primarily at risk from CVE-2012-1578?
Users with block permission in MediaWiki are primarily at risk from CVE-2012-1578.