An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| mediawiki/core(Packagist) | 1.27.0 | 1.27.6 | N/A |
| mediawiki/core(Packagist) | 1.30.0 | 1.30.2 | N/A |
| mediawiki/core(Packagist) | 1.31.0 | 1.31.2 | N/A |
| mediawiki/core(Packagist) | 1.32.0 | 1.32.2 | N/A |
CVSS Metrics