First published: Tue Sep 01 2015(Updated: )
The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | <=1.23.9 | |
MediaWiki | =1.24.0 | |
MediaWiki | =1.24.1 | |
MediaWiki | =1.24.2 | |
MediaWiki | =1.25.0 | |
MediaWiki | =1.25.1 | |
Ubuntu | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-6727 is considered moderate as it allows remote attackers to infer information about IP autoblocks.
To fix CVE-2015-6727, you should upgrade MediaWiki to version 1.23.10, 1.24.3, or 1.25.2 or later.
Versions of MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 are affected by CVE-2015-6727.
CVE-2015-6727 is an information disclosure vulnerability that affects MediaWiki.
Yes, CVE-2015-6727 can potentially be exploited by remote attackers without authentication, making it a concern for exposed MediaWiki installations.