thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mediawiki | Jul 30, 2024 | Mar 31, 2010 |
| Mediawiki | — | Upgrade MediaWiki to the latest version | Aug 24, 2017 | Mar 31, 2010 |
| Suse | — | Upgrade mediawiki | Feb 17, 2015 | Mar 31, 2010 |
| Ubuntu | — | Upgrade mediawiki | Nov 19, 2024 | Mar 31, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub