MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2012-09-09 14:55
Updated : 2017-08-28 18:31
NVD link : CVE-2012-1581
Mitre link : CVE-2012-1581
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
mediawiki
- mediawiki