CVE-2015-8625

high

Description

MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters.

References

https://phabricator.wikimedia.org/T118032

https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-December/000186.html

http://www.openwall.com/lists/oss-security/2015/12/23/7

http://www.openwall.com/lists/oss-security/2015/12/21/8

Details

Source: Mitre, NVD

Published: 2017-03-23

Updated: 2017-03-27

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High