First published: Thu Mar 23 2017(Updated: )
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <=1.23.11 | |
MediaWiki MediaWiki | =1.24.0 | |
MediaWiki MediaWiki | =1.24.1 | |
MediaWiki MediaWiki | =1.24.2 | |
MediaWiki MediaWiki | =1.24.3 | |
MediaWiki MediaWiki | =1.24.4 | |
MediaWiki MediaWiki | =1.25.0 | |
MediaWiki MediaWiki | =1.25.1 | |
MediaWiki MediaWiki | =1.25.2 | |
MediaWiki MediaWiki | =1.25.3 | |
MediaWiki MediaWiki | =1.26.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.