vulnerability

MediaWiki: Information Exposure (CVE-2013-6455)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jan 28, 2020
Added
Feb 3, 2020
Modified
Mar 7, 2024

Description

The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.

Solutions

mediawiki-upgrade-1_19_10mediawiki-upgrade-1_21_4mediawiki-upgrade-1_22_1
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.