CVE Database
/

CVE-2012-4381

Back to search

CVE-2012-4381

Published: Feb 8, 2020

Modified: Aug 6, 2024

PUBLISHED

Description

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

VendorProductVersions

n/a

MediaWiki

affected
before 1.18.5
affected
1.19.x before 1.19.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now