CVE-2019-12472: Mediawiki
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Affected products
- Mediawiki Mediawiki: from 1.18.0, before 1.27.6 (fixed in 1.27.6); from 1.30.0, before 1.30.2 (fixed in 1.30.2); from 1.31.0, before 1.31.2 (fixed in 1.31.2); from 1.32.0, before 1.32.2 (fixed in 1.32.2)
Published 2019-07-10. Last modified 2026-06-17.