MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.
2012-09-09T21:55:06.137
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mediawiki | mediawiki | 1.17 | Yes |
Application | mediawiki | mediawiki | 1.17 | Yes |
Application | mediawiki | mediawiki | 1.17.0 | Yes |
Application | mediawiki | mediawiki | 1.17.0 | Yes |
Application | mediawiki | mediawiki | 1.17.1 | Yes |
Application | mediawiki | mediawiki | 1.17.2 | Yes |
Application | mediawiki | mediawiki | 1.18 | Yes |
Application | mediawiki | mediawiki | 1.18 | Yes |
Application | mediawiki | mediawiki | 1.18.0 | Yes |
Application | mediawiki | mediawiki | 1.18.0 | Yes |
Application | mediawiki | mediawiki | 1.18.1 | Yes |