Loading...
Loading...
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.
November 18, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-2032
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.