CVE-2019-18987
Last modified
CVE-2019-18987 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Abusefilter | <= 1.34 |
References
- https://gerrit.wikimedia.org/r/q/Ic12790bd33982473f77551bde9599ed083a3e1f1Patch, Third Party Advisory
- https://phabricator.wikimedia.org/T237887Issue Tracking, Patch, Third Party Advisory
- https://www.mediawiki.org/wiki/Extension:AbuseFilterProduct, Vendor Advisory
- https://gerrit.wikimedia.org/r/q/Ic12790bd33982473f77551bde9599ed083a3e1f1Patch, Third Party Advisory
- https://phabricator.wikimedia.org/T237887Issue Tracking, Patch, Third Party Advisory
- https://www.mediawiki.org/wiki/Extension:AbuseFilterProduct, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-18987?
How severe is CVE-2019-18987?
How do I fix CVE-2019-18987?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1898A vulnerability in the web-based management interface of Cis…5.3
- CVE-2019-18980On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bu…7.5
- CVE-2019-18981Pimcore before 6.2.2 lacks an Access Denied outcome for a ce…9.8
- CVE-2019-18982bundles/AdminBundle/Controller/Admin/EmailController.php in …6.1
- CVE-2019-18985Pimcore before 6.2.2 lacks brute force protection for the 2F…9.8
- CVE-2019-18986Pimcore before 6.2.2 allow attackers to brute-force (guess) …7.5
- CVE-2019-18988TeamViewer Desktop through 14.7.1965 allows a bypass of remo…7
- CVE-2019-18989A partial authentication bypass vulnerability exists on Medi…5.4
- CVE-2019-1899A vulnerability in the web interface of Cisco RV110W, RV130W…5.3
- CVE-2019-18990A partial authentication bypass vulnerability exists on Real…5.4
- CVE-2019-18991A partial authentication bypass vulnerability exists on Athe…5.4
- CVE-2019-18992OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-…5.4
Are you affected by CVE-2019-18987?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
