Security Advisory
CVE-2012-1581
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.