Session Cookie Vulnerability in MediaWiki CentralNotice Extension
CVE-2013-4572
7.5HIGH
What is CVE-2013-4572?
The MediaWiki CentralNotice extension prior to specific versions improperly sets the Cache-Control header, leading to caching of session cookies when a user account is auto-created. This misconfiguration allows remote attackers to exploit the vulnerability by authenticating as the newly created user without appropriate authorization, posing a significant security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MediaWiki before 1.19.9
MediaWiki 1.20.x before 1.20.8
MediaWiki 1.21.x before 1.21.3
