Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/201510-05 | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2015:200 | vendor advisory |
http://www.securityfocus.com/bid/73477 | vdb entry |
http://www.openwall.com/lists/oss-security/2015/04/07/3 | mailing list |
http://www.openwall.com/lists/oss-security/2015/04/01/1 | mailing list |
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html | mailing list patch vendor advisory |
https://phabricator.wikimedia.org/T85858 |