Unrated severityNVD Advisory· Published Jan 8, 2012· Updated Apr 29, 2026
CVE-2011-4361
CVE-2011-4361
Description
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
Affected products
3cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.htmlnvdPatchVendor Advisory
- bugzilla.wikimedia.org/show_bug.cginvdIssue TrackingPatchVendor Advisory
- openwall.com/lists/oss-security/2011/11/29/12nvdMailing ListThird Party Advisory
- openwall.com/lists/oss-security/2011/11/29/6nvdMailing ListThird Party Advisory
- www.debian.org/security/2011/dsa-2366nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.