Permissions, Privileges, and Access Controls in MediaWiki - CVE-2015-8004

 

Permissions, Privileges, and Access Controls in MediaWiki - CVE-2015-8004

Published: November 9, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40600
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2015-8004
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: MediaWiki.org
Affected software:
MediaWiki

Detailed vulnerability description

The vulnerability allows a remote #AU# to manipulate data.

MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not properly restrict access to revisions, which allows remote authenticated users with the viewsuppressed user right to remove revision suppressions via a crafted revisiondelete action, which returns a valid a change form.


How to mitigate CVE-2015-8004

Install update from vendor's website.

Sources