CVE-2015-2940
Summary
| CVE | CVE-2015-2940 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-13 14:59:13 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MediaWiki: Multiple vulnerabilities (GLSA 201510-05) — Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| oss-security - CVE request: MediaWiki 1.24.2/1.23.9/1.19.24 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Support / Security / Advisories / / MDVSA-2015:200 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| [MediaWiki-announce] MediaWiki Security and Maintenance Releases: 1.19.24, 1.23.9, and 1.24.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.wikimedia.org | Patch, Vendor Advisory |
| MediaWiki Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| ⚓ T85858 Check User page lacks CSRF protection | af854a3a-2127-422b-91ae-364da2661108 | phabricator.wikimedia.org | |
| oss-security - Re: CVE request: MediaWiki 1.24.2/1.23.9/1.19.24 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.