Skip to content

CVE-2012-5395

Session fixation vulnerability in the CentralAuth extension for MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the centralauth_Session cookie.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0054 (0.5%)
Percentile: 67.6%
EPSS: 2026-05-06

Affects

mediawiki:mediawiki

Technical description

Session fixation vulnerability in the CentralAuth extension for MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the centralauth_Session cookie.

Published: 6/2/2014, 3:55:08 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam