CVE-2020-15164 CRITICAL

CVE-2020-15164: Authentication Bypass in Scratch Login (mediawiki-scratch-login)

Vendor Internationalscratchwiki
Product mediawiki-scratch-login
Weakness CWE-287 · Improper authentication
Published August 28, 2020
Last update August 4, 2024

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whitespace and trimmed by MediaWiki. This affects all users on any wiki using this extension. Since version 1.1, comments by users whose usernames would be trimmed on MediaWiki are ignored when searching for the verification code.

Key dates

02Disclosure timeline

August 28, 2020 CVE published
August 4, 2024 Record updated