Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whxp-588c-mcgq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.

An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.

EPSS

Процентиль: 30%
0.0011
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.

EPSS

Процентиль: 30%
0.0011
Низкий

Дефекты

CWE-352