VDB
GCVE-VVD-MAGEIA-2019-279
GCVE-VVD-MAGEIA-2019-279
Advisory Published
Updated mediawiki packages fix security vulnerabilities:
Potential XSS in jQuery (CVE-2019-11358).
An account can be logged out without using a token (CSRF) (CVE-2019-12466).
A spammer can use Special:ChangeEmail to send out spam with no rate limiting
or ability to block them (CVE-2019-12467).
Directly POSTing to Special:ChangeEmail would allow for bypassing
reauthentication, allowing for potential account takeover (CVE-2019-12468).
Exposed suppressed username or log in Special:EditTags (CVE-2019-12469).
Exposed suppressed log in RevisionDelete page (CVE-2019-12470).
Loading user JavaScript from a non-existent account allows anyone to create
the account, and XSS the users' loading that script (CVE-2019-12471).
It is possible to bypass the limits on IP range blocks (`$wgBlockCIDRLimit`)
by using the API (CVE-2019-12472).
Passing invalid titles to the API could cause a DoS by querying the entire
`watchlist` table (CVE-2019-12473).
Privileged API responses that include whether a recent change has been
patrolled may be cached publicly (CVE-2019-12474).
The mediawiki package has been updated to version 1.27.6 (Mageia 6) and 1.31.2
(Mageia 7), fixing these issues and other bugs. See the release announcements
for more details.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | mediawiki | 0 (affected), 1.31.3-1.mga7 (unaffected) | — |
| Mageia | mediawiki | 0 (affected), 1.27.7-1.mga6 (unaffected) | — |
Aliases
CVE-2019-12469CVE-2019-12467CVE-2019-12468CVE-2019-12473CVE-2019-12471CVE-2019-12470CVE-2019-12474CVE-2019-12466CVE-2019-12472
Transitive aliases
BDU:2019-03622EUVD-2022-2862CNVD-2019-36874BDU:2019-03562CNVD-2019-36872GHSA-33xw-x3pr-rvqjGSD-2019-12472BDU:2020-02564GSD-2019-12474BDU:2019-03617GSD-2019-12467CNVD-2019-36868EUVD-2022-5698GHSA-wrhx-3pxr-6vggBDU:2019-03619CNVD-2019-36871GSD-2019-12473GHSA-27fw-r78j-h898CNVD-2019-36873GHSA-2qrr-c2gh-pr35BDU:2019-03618EUVD-2022-2100CNVD-2019-36875GHSA-7mqg-5fgh-xh4rBDU:2019-03621EUVD-2022-1931CNVD-2019-36870GSD-2019-12471GHSA-733q-m38x-q7ccGSD-2019-12466GHSA-x3fr-w7r5-x7rgGSD-2019-12469GHSA-2rm7-xxx8-35jhEUVD-2022-5631GSD-2019-12470EUVD-2022-2898GHSA-6vfg-8ppv-h5hgBDU:2019-03563EUVD-2022-3036EUVD-2022-2043GSD-2019-12468CNVD-2019-36869EUVD-2022-2038BDU:2019-03620
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.