CVE-2012-1581

MediaWiki 1.17.x < 1.17.3 and 1.18.x < 1.18.2 - Weak Password Reset Token Randomness

Title source: llm
STIX 2.1

Description

MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.

References (8)

Core 8
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.wikimedia.org/show_bug.cgi?id=35078
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/03/24/1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48504
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78910
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/03/22/9
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52689

Scores

EPSS 0.0054
EPSS Percentile 67.8%

Details

CWE
CWE-264
Status published
Products (7)
mediawiki/mediawiki 1.17 (2 CPE variants)
mediawiki/mediawiki 1.17.0 (2 CPE variants)
mediawiki/mediawiki 1.17.1
mediawiki/mediawiki 1.17.2
mediawiki/mediawiki 1.18 (2 CPE variants)
mediawiki/mediawiki 1.18.0 (2 CPE variants)
mediawiki/mediawiki 1.18.1
Published Sep 09, 2012
Tracked Since Feb 18, 2026