The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 allow remote attackers to obtain sensitive user login information via crafted links combined with page view statistics.
References
Link Resource
http://www.openwall.com/lists/oss-security/2015/12/21/8 Mailing List Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2015/12/23/7 Mailing List Patch Third Party Advisory
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-December/000186.html Patch Release Notes Vendor Advisory
https://phabricator.wikimedia.org/T109724 Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-03-23T20:00:00

Updated: 2017-03-23T19:57:01

Reserved: 2015-12-23T00:00:00


Link: CVE-2015-8628

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-03-23T20:59:00.687

Modified: 2017-03-28T17:15:39.443


Link: CVE-2015-8628

JSON object: View

cve-icon Redhat Information

No data.

CWE