CVE-2018-0505

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
04/10/2018
Last modified:
18/10/2019

Description

Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.31.0 (including) 1.31.1 (excluding)
cpe:2.3:a:mediawiki:mediawiki:1.27.5:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.29.3:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.30.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*