CVE-2015-8625: Infoleak
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8625?
CVE-2015-8625 is classified as a medium severity vulnerability due to the risk of unauthorized file access.
How do I fix CVE-2015-8625?
To fix CVE-2015-8625, upgrade MediaWiki to version 1.23.12, 1.24.5, 1.25.4, or 1.26.1 or later.
Which versions of MediaWiki are affected by CVE-2015-8625?
MediaWiki versions before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 are vulnerable.
What type of attacks can CVE-2015-8625 enable?
CVE-2015-8625 allows remote attackers to read arbitrary files on the server through improper parameter sanitization.
Is user data at risk due to CVE-2015-8625?
Yes, user data may be at risk if an attacker exploits CVE-2015-8625 to access sensitive files.