VYPR
Unrated severityNVD Advisory· Published Sep 9, 2012· Updated Apr 29, 2026

CVE-2012-1580

CVE-2012-1580

Description

Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload files.

Affected products

11
  • MediaWiki/Mediawiki11 versions
    cpe:2.3:a:mediawiki:mediawiki:1.17:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:mediawiki:mediawiki:1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.17:beta_1:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.18:beta_1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.