First published: Mon Apr 13 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki CheckUser |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2940 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive user information.
To mitigate CVE-2015-2940, update the CheckUser extension for MediaWiki to the latest version that addresses this CSRF vulnerability.
CVE-2015-2940 allows attackers to perform cross-site request forgery (CSRF) attacks that can hijack user authentication and access sensitive data.
Users of the CheckUser extension for MediaWiki are at risk from CVE-2015-2940, specifically those with permissions that allow access to sensitive user information.
While upgrading the extension is the best fix, ensuring that CSRF protections are in place can provide temporary relief from CVE-2015-2940.