Description
MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.
Remediation
References
Related Vulnerabilities
WordPress Plugin Newsletter-Send awesome emails from WordPress Cross-Site Scripting (3.2.6)
Apache Tomcat Always-Incorrect Control Flow Implementation Vulnerability (CVE-2026-53404)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-2854)
PHP Resource Management Errors Vulnerability (CVE-2010-4697)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Cross-Site Scripting (5.2.2)