Back to overview

CVE-2020-15164

CRITICAL
10.0
CVSS 3.1
Description
in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whitespace and trimmed by MediaWiki. This affects all users on any wiki using this extension. Since version 1.1, comments by users whose usernames would be trimmed on MediaWiki are ignored when searching for the verification code.

Metadata

CVE ID
CVE-2020-15164
State
PUBLISHED
Assigner
GitHub_M
Reserved
2020-06-25 00:00 UTC
Published
2020-08-28 17:05 UTC
Last updated
2024-08-04 13:08 UTC
Primary CWE
CWE-287
CWE-287: Improper Authentication
Vendor / Product
InternationalScratchWiki / mediawiki-scratch-login
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Affected products (1)
VendorProductPlatformVersions
InternationalScratchWiki mediawiki-scratch-login < 1.1
Weakness (CWE)
CWESourceDescription
CWE-287 cna CWE-287: Improper Authentication
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Back to overview