Description
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-1999-1148)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9735)
Squid Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9749)
Joomla! Core 3.x.x Security Bypass (3.0.0 - 3.2.2)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3558)