CVE-2015-8008
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allow
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.
HIGH · CVSS 7.5
EPSS 0.00548
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0