Back

CVE-2019-12468

CRITICAL

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.

Published: Jul 10, 2019 Modified: Jun 17, 2026
CWE-306

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
mediawiki mediawiki * ≥ 1.27.0
debian debian_linux 9.0

GitHub Security Advisory GHSA-wrhx-3pxr-6vgg

Wikimedia MediaWiki Incorrect Access Control vulnerability

composer mediawiki/core >= 1.27.0, < 1.27.6 Fixed: 1.27.6
composer mediawiki/core >= 1.30.0, < 1.30.2 Fixed: 1.30.2
composer mediawiki/core >= 1.31.0, < 1.31.2 Fixed: 1.31.2
composer mediawiki/core >= 1.32.0, < 1.32.2 Fixed: 1.32.2

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.43%

Top 12% most likely to be exploited

Threat Score 40.2 / 100

Data Sources

NVD EPSS GitHub