| ID | CVE-2012-4381 | ||||||
| Sažetak | MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:M/Au:N/C:C/I:C/A:C | ||||||
| Zadnje važnije ažuriranje | 12-02-2020 - 18:48 | ||||||
| Objavljeno | 08-02-2020 - 18:15 |

