Skip to content

Authentication Bypass by Alternate Name

Critical
Kenny2github published GHSA-8fq5-g4m5-6j43 Aug 28, 2020

Package

No package listed

Affected versions

<1.1

Patched versions

1.1

Description

Impact

Affects all users on any wiki using this extension. Any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whitespace and trimmed by MediaWiki.

Patches

Since version 1.1, comments by users whose usernames would be trimmed on MediaWiki are ignored when searching for the verification code.

Workarounds

  • Disable the extension (remove wfLoadExtension( 'ScratchLogin' ) or wfLoadExtension( 'mediawiki-scratch-login' ))
  • If you still want to use the extension, update your version of the extension now.

Severity

Critical

CVE ID

CVE-2020-15164

Weaknesses

No CWEs

Credits