MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain…
redhat·CWE-276·Published 2012-01-08