CVE-2013-4572: vulnerability in Wikimedia Foundation MediaWiki
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.1%
exploitation probability
2.1%top 19% of all CVEs
observed exploitation
nono source reports it
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
Affected products
Wikimedia Foundation · MediaWikiRelated CVEs — Wikimedia Foundation MediaWiki
In the same product, most dangerous first.
CVE-2013-4303—CVE-2013-4303EPSS 1.5%CVE-2013-6455—CVE-2013-6455EPSS 1.1%CVE-2013-6451—CVE-2013-6451EPSS 1.1%CVE-2025-6597NONEMediaWiki should not consider autocreation as login for the purposes of security reauthenticationEPSS 0.5%CVE-2025-6927LOWAutoblocks from global account suppressions are publicly visibleEPSS 0.5%CVE-2026-58025MEDIUMRemote Code Execution via Unsafe Deserialization in LogItem ImportEPSS 0.5%
References
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/122998.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/123011.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2013-November/000135.htmlhttps://bugzilla.wikimedia.org/show_bug.cgi?id=53032