Unrated severityNVD Advisory· Published Sep 9, 2012· Updated Apr 29, 2026
CVE-2012-1580
CVE-2012-1580
Description
Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload files.
Affected products
11cpe:2.3:a:mediawiki:mediawiki:1.17:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:mediawiki:mediawiki:1.17:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17.2:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17:beta_1:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18:beta_1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000109.htmlnvdVendor Advisory
- lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000110.htmlnvdVendor Advisory
- secunia.com/advisories/48504nvdVendor Advisory
- osvdb.org/80364nvd
- www.openwall.com/lists/oss-security/2012/03/22/9nvd
- www.openwall.com/lists/oss-security/2012/03/24/1nvd
- www.securityfocus.com/bid/52689nvd
- bugzilla.wikimedia.org/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/74286nvd
News mentions
0No linked articles in our index yet.