Description
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.
Remediation
References
Related Vulnerabilities
phpMyAdmin Other Vulnerability (CVE-2005-3787)
Oracle Database Server Other Vulnerability (CVE-2003-0727)
Apache Traffic Server Uncontrolled Resource Consumption Vulnerability (CVE-2018-8005)
MySQL CVE-2015-0505 Vulnerability (CVE-2015-0505)
WordPress Plugin Comments-wpDiscuz Cross-Site Scripting (3.1.4)