CVE-2015-8628: Infoleak
The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 allow remote attackers to obtain sensitive user login information via crafted links combined with page view statistics.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8628?
CVE-2015-8628 is classified as a high severity vulnerability due to its potential to expose sensitive user login information.
Which versions of MediaWiki are affected by CVE-2015-8628?
CVE-2015-8628 affects MediaWiki versions prior to 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1.
How do I fix CVE-2015-8628?
To fix CVE-2015-8628, upgrade MediaWiki to the latest version that is not vulnerable.
What kind of information can be obtained through CVE-2015-8628?
CVE-2015-8628 allows attackers to obtain sensitive user login information by exploiting vulnerable pages.
Can CVE-2015-8628 be exploited remotely?
Yes, CVE-2015-8628 can be exploited by remote attackers without requiring any local access.