CVE-2015-8625
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters.
- Mediawiki
- ≤ 1.23.11, 1.24.0, 1.24.1, 1.24.2, 1.24.3, 1.24.4, 1.25.0, 1.25.1, 1.25.2, 1.25.3, 1.26.0
- Fix
- Available
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 1.8% (76th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2017-03-23
CVE-2015-8625 at NVD
No indexed exploits for CVE-2015-8625 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2015-8625 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.