MediaWiki contains a flaw related to external authentication plugins. The issue is triggered when the plugin returns false in its strict function. This may allow an attacker to use an old password for an account indefinitely.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 1.18.5 or 1.19.2 or higher, as they have been reported to fix this vulnerability.