CVE-2015-6728

Source
https://cve.org/CVERecord?id=CVE-2015-6728
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2015-6728.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2015-6728
Downstream
Published
2015-09-01T14:59:06Z
Modified
2026-04-10T03:46:26.700742Z
Summary
[none]
Details

The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison in constant time, which allows remote attackers to guess the watchlist token and bypass CSRF protection via a timing attack.

References

Affected packages