CVE-2012-5391: Mediawiki

Medium severity, CVSS 6.8. EPSS: 2.3% chance of exploitation in the next 30 days.

Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.

Affected products

  • Mediawiki Mediawiki: up to and including 1.18.5; version 1.18 only; version 1.18.0 only; version 1.18.1 only; version 1.18.2 only; version 1.18.3 only; …

Published 2014-06-02. Last modified 2026-06-16.