CVE-2019-12472
Debian Security Advisory 4460-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Se encontró una vulnerabilidad de Control de Acceso Incorrecto en MediaWiki versiones 1.18.0 hasta 1.32.1 de Wikimedia. Es posible omitir los límites en los bloques de rango IP ($wgBlockCIDRLimit) mediante el uso de la API. Se corrigió en las versiones 1.32.2, 1.31.2, 1.30.2 y 1.27.6.
Multiple security vulnerabilities have been discovered in MediaWiki, a website engine for collaborative work, which may result in authentication bypass, denial of service, cross-site scripting, information disclosure and bypass of anti-spam measures.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-05-30 CVE Reserved
- 2019-06-12 CVE Published
- 2024-08-04 CVE Updated
- 2025-07-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://phabricator.wikimedia.org/T199540 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://lists.wikimedia.org/pipermail/wikitech-l/2019-June/092152.html | 2020-08-24 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | >= 1.18.0 < 1.27.6 Search vendor "Mediawiki" for product "Mediawiki" and version " >= 1.18.0 < 1.27.6" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | >= 1.30.0 < 1.30.2 Search vendor "Mediawiki" for product "Mediawiki" and version " >= 1.30.0 < 1.30.2" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | >= 1.31.0 < 1.31.2 Search vendor "Mediawiki" for product "Mediawiki" and version " >= 1.31.0 < 1.31.2" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | >= 1.32.0 < 1.32.2 Search vendor "Mediawiki" for product "Mediawiki" and version " >= 1.32.0 < 1.32.2" | - |
Affected
|