Description
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
Remediation
References
Related Vulnerabilities
Atlassian Jira Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-41307)
WordPress Plugin Contact Form DB Multiple Cross-Site Scripting Vulnerabilities (2.8.15)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.8)
WordPress Plugin Custom Login Page Customizer-LoginPress Unspecified Vulnerability (1.1.15)