CVE-2012-5395: Mediawiki

Medium severity, CVSS 6.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Session fixation vulnerability in the CentralAuth extension for MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the centralauth_Session cookie.

Affected products

  • Mediawiki Mediawiki: version 1.20 only; version 1.19 only; version 1.19.1 only; version 1.19.2 only; up to and including 1.18.5; version 1.18 only; …

Published 2014-06-02. Last modified 2026-06-16.