Lucene search

K
cveMitreCVE-2015-2940
HistoryApr 13, 2015 - 2:59 p.m.

CVE-2015-2940

2015-04-1314:59:13
CWE-352
mitre
web.nvd.nist.gov
35
cve-2015-2940
csrf
checkuser extension
mediawiki
remote attackers
authentication hijacking
sensitive user information

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.003

Percentile

70.6%

Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors.

Affected configurations

Nvd
Node
mediawikicheckuserMatch-mediawiki
VendorProductVersionCPE
mediawikicheckuser-cpe:2.3:a:mediawiki:checkuser:-:*:*:*:*:mediawiki:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.003

Percentile

70.6%