← Back to CVE List

CVE-2015-8625

Published: 2017-03-23T20:59Z
Last Modified: 2024-11-21T02:38Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt