CVE-2012-1581
MediaWiki 1.17.x < 1.17.3 and 1.18.x < 1.18.2 - Weak Password Reset Token Randomness
Title source: llmDescription
MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.
References (8)
Core 8
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.wikimedia.org/show_bug.cgi?id=35078
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/03/24/1
Vendor Advisory mailing-list
x_refsource_mlist
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000110.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48504
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78910
Vendor Advisory mailing-list
x_refsource_mlist
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000109.html
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/03/22/9
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/52689
Scores
EPSS
0.0054
EPSS Percentile
67.8%
Details
CWE
CWE-264
Status
published
Products (7)
mediawiki/mediawiki
1.17 (2 CPE variants)
mediawiki/mediawiki
1.17.0 (2 CPE variants)
mediawiki/mediawiki
1.17.1
mediawiki/mediawiki
1.17.2
mediawiki/mediawiki
1.18 (2 CPE variants)
mediawiki/mediawiki
1.18.0 (2 CPE variants)
mediawiki/mediawiki
1.18.1
Published
Sep 09, 2012
Tracked Since
Feb 18, 2026