Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://phabricator.wikimedia.org/T372209 | vendor advisory issue tracking exploit |
https://phabricator.wikimedia.org/T368628 | vendor advisory issue tracking |
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1062723 | patch |