MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2012-09-09T21:00:00
Updated: 2017-08-28T12:57:01
Reserved: 2012-03-12T00:00:00
Link: CVE-2012-1581
JSON object: View
NVD Information
Status : Modified
Published: 2012-09-09T21:55:06.137
Modified: 2017-08-29T01:31:19.287
Link: CVE-2012-1581
JSON object: View
Redhat Information
No data.
CWE