CVE-2012-1580

medium
Published 2012-09-09 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload files.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-1580

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48504

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000110.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000109.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Application impact

VendorProductVersionsFixed
mediawikimediawiki1.17
mediawikimediawiki1.17.0
mediawikimediawiki1.17.1
mediawikimediawiki1.17.2
mediawikimediawiki1.18
mediawikimediawiki1.18.0
mediawikimediawiki1.18.1

References

CWEs

CWE-352

Verify integrity in audit chain (admin only). AS-IS.