MediaWiki < 1.19.14 / 1.21.8 / 1.22.5 ChangePassword XSRF

medium Nessus Plugin ID 73305

Synopsis

The remote web server contains an application that is affected by a cross-site request forgery vulnerability.

Description

According to its version number, the instance of MediaWiki running on the remote host is affected by a cross-site request forgery vulnerability.

A flaw exists with Special:ChangePassword within the includes/specials/SpecialChangePassword.php script where HTTP requests do not require explicit confirmation, a unique token, and/or multiple steps performing sensitive actions. This allows a context-dependent attacker to reset a user's password.

Nessus has not tested for this issue but has instead relied on the application's self-reported version number.

Solution

Upgrade to MediaWiki version 1.19.15 / 1.21.8 / 1.22.5 or later.

Note that a fix for this issue was implemented with 1.19.14 but the patch contains a mistake; users of 1.19.x should update to 1.19.15.

See Also

http://www.nessus.org/u?78c1dedb

http://www.nessus.org/u?279f2f2c

https://www.mediawiki.org/wiki/Release_notes/1.19

https://www.mediawiki.org/wiki/Release_notes/1.21

https://www.mediawiki.org/wiki/Release_notes/1.22

https://phabricator.wikimedia.org/T64497

http://www.nessus.org/u?7505c42f

https://phabricator.wikimedia.org/T64497#c14

Plugin Details

Severity: Medium

ID: 73305

File Name: mediawiki_1_19_14.nasl

Version: 1.11

Type: remote

Family: CGI abuses

Published: 4/2/2014

Updated: 6/5/2024

Configuration: Enable paranoid mode, Enable thorough checks

Supported Sensors: Nessus

Enable CGI Scanning: true

Risk Information

VPR

Risk Factor: Low

Score: 2.7

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:mediawiki:mediawiki

Required KB Items: www/PHP, Settings/ParanoidReport, installed_sw/MediaWiki

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No known exploits are available

Patch Publication Date: 3/28/2014

Vulnerability Publication Date: 3/10/2014

Reference Information

CVE: CVE-2014-2665

BID: 66600