Unrated severityNVD Advisory· Published Jan 8, 2012· Updated Jun 16, 2026
CVE-2011-4361
CVE-2011-4361
Description
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
6- lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.htmlnvdPatchVendor Advisory
- bugzilla.wikimedia.org/show_bug.cginvdIssue TrackingPatchVendor Advisory
- openwall.com/lists/oss-security/2011/11/29/12nvdMailing ListThird Party Advisory
- openwall.com/lists/oss-security/2011/11/29/6nvdMailing ListThird Party Advisory
- www.debian.org/security/2011/dsa-2366nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.