{"api_version":"1","generated_at":"2026-05-13T11:00:57+00:00","cve":"CVE-2015-2940","urls":{"html":"https://cve.report/CVE-2015-2940","api":"https://cve.report/api/cve/CVE-2015-2940.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-2940","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-2940"},"summary":{"title":"CVE-2015-2940","description":"Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-04-13 14:59:13","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-352","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://security.gentoo.org/glsa/201510-05","name":"https://security.gentoo.org/glsa/201510-05","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MediaWiki: Multiple vulnerabilities (GLSA 201510-05) — Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2015/04/01/1","name":"http://www.openwall.com/lists/oss-security/2015/04/01/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE request: MediaWiki 1.24.2/1.23.9/1.19.24","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:200","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:200","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support / Security / Advisories /  / MDVSA-2015:200 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html","name":"https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"[MediaWiki-announce] MediaWiki Security and Maintenance Releases:\t1.19.24, 1.23.9, and 1.24.2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/73477","name":"http://www.securityfocus.com/bid/73477","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MediaWiki Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://phabricator.wikimedia.org/T85858","name":"https://phabricator.wikimedia.org/T85858","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"⚓ T85858 Check User page lacks CSRF protection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2015/04/07/3","name":"http://www.openwall.com/lists/oss-security/2015/04/07/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: CVE request: MediaWiki 1.24.2/1.23.9/1.19.24","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-2940","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-2940","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"2940","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mediawiki","cpe5":"checkuser","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"mediawiki","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:32:20.467Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"GLSA-201510-05","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201510-05"},{"name":"MDVSA-2015:200","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:200"},{"name":"73477","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/73477"},{"name":"[oss-security] 20150407 Re: CVE request: MediaWiki 1.24.2/1.23.9/1.19.24","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2015/04/07/3"},{"name":"[oss-security] 20150331 CVE request: MediaWiki 1.24.2/1.23.9/1.19.24","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2015/04/01/1"},{"name":"[MediaWiki-announce] 20150331 MediaWiki Security and Maintenance Releases: 1.19.24, 1.23.9, and 1.24.2","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://phabricator.wikimedia.org/T85858"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-03-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-05T21:57:02.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"GLSA-201510-05","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201510-05"},{"name":"MDVSA-2015:200","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:200"},{"name":"73477","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/73477"},{"name":"[oss-security] 20150407 Re: CVE request: MediaWiki 1.24.2/1.23.9/1.19.24","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2015/04/07/3"},{"name":"[oss-security] 20150331 CVE request: MediaWiki 1.24.2/1.23.9/1.19.24","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2015/04/01/1"},{"name":"[MediaWiki-announce] 20150331 MediaWiki Security and Maintenance Releases: 1.19.24, 1.23.9, and 1.24.2","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://phabricator.wikimedia.org/T85858"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-2940","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"GLSA-201510-05","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201510-05"},{"name":"MDVSA-2015:200","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:200"},{"name":"73477","refsource":"BID","url":"http://www.securityfocus.com/bid/73477"},{"name":"[oss-security] 20150407 Re: CVE request: MediaWiki 1.24.2/1.23.9/1.19.24","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/04/07/3"},{"name":"[oss-security] 20150331 CVE request: MediaWiki 1.24.2/1.23.9/1.19.24","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/04/01/1"},{"name":"[MediaWiki-announce] 20150331 MediaWiki Security and Maintenance Releases: 1.19.24, 1.23.9, and 1.24.2","refsource":"MLIST","url":"https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html"},{"name":"https://phabricator.wikimedia.org/T85858","refsource":"CONFIRM","url":"https://phabricator.wikimedia.org/T85858"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-2940","datePublished":"2015-04-13T14:00:00.000Z","dateReserved":"2015-04-07T00:00:00.000Z","dateUpdated":"2024-08-06T05:32:20.467Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-04-13 14:59:13","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-352","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:checkuser:-:*:*:*:*:mediawiki:*:*","matchCriteriaId":"AF8654AE-7741-4CD6-A1C1-1C70CF29DEED"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"2940","Ordinal":"1","Title":"CVE-2015-2940","CVE":"CVE-2015-2940","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"2940","Ordinal":"1","NoteData":"Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors.","Type":"Description","Title":"CVE-2015-2940"},{"CveYear":"2015","CveId":"2940","Ordinal":"2","NoteData":"2015-04-13","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"2940","Ordinal":"3","NoteData":"2016-12-05","Type":"Other","Title":"Modified"}]}}}