Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x before 1.13.3 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html | vendor advisory |
http://www.debian.org/security/2009/dsa-1901 | vendor advisory |
http://secunia.com/advisories/33133 | third party advisory patch vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html | vendor advisory |
http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html | mailing list patch vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.html | vendor advisory |
http://secunia.com/advisories/33349 | third party advisory |