First published: Wed Nov 20 2019(Updated: )
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | 1:1.35.13-1+deb11u2 1:1.39.7-1~deb12u1 1:1.39.8-1 | |
Wikimedia MediaWiki | <1.19.4 | |
Wikimedia MediaWiki | >=1.20.0<1.20.3 | |
Debian | =9.0 | |
Debian | =10.0 | |
Red Hat Enterprise Linux | =6.0 | |
Fedora | =18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1817 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2013-1817, upgrade MediaWiki to version 1.19.4, 1.20.3, or later versions.
CVE-2013-1817 affects MediaWiki versions before 1.19.4 and between 1.20.0 and 1.20.3.
CVE-2013-1817 is an information disclosure vulnerability that allows remote attackers to access sensitive data.
CVE-2013-1817 exploits an error in the api.php script in MediaWiki, allowing unauthorized data retrieval.