CVE-2013-2032

Source
https://cve.org/CVERecord?id=CVE-2013-2032
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2013-2032.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2013-2032
Downstream
Withdrawn
2026-01-27T04:13:09.222421Z
Published
2013-11-18T02:55:07Z
Modified
2026-01-27T04:13:09.222421Z
Summary
[none]
Details

MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.

References

Affected packages