Vulnerability in Wikimedia Foundation OATHAuth. This vulnerability is associated with program files src/Special/OATHManage.Php.
This issue affects OATHAuth: from * before 1.39.14, 1.43.4, 1.44.1.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wikimedia
Wikimedia oathauth |
|
| Vendors & Products |
Wikimedia
Wikimedia oathauth |
Tue, 03 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in Wikimedia Foundation OATHAuth. This vulnerability is associated with program files src/Special/OATHManage.Php. This issue affects OATHAuth: from * before 1.39.14, 1.43.4, 1.44.1. | |
| Title | Reauth for enabling 2FA can be bypassed by submitting a form | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: wikimedia-foundation
Published: 2026-02-03T00:27:45.487Z
Updated: 2026-02-03T21:08:02.478Z
Reserved: 2025-09-29T17:49:52.146Z
Link: CVE-2025-11173
Updated: 2026-02-03T21:07:59.308Z
Status : Awaiting Analysis
Published: 2026-02-03T01:15:57.360
Modified: 2026-02-03T16:44:03.343
Link: CVE-2025-11173
No data.